MoonWalk is a backdoor malware family associated in the provided content with Wicked Panda (APT41). It was described in campaigns active from May 2021 to February 2022 targeting U.S. state government networks and Taiwanese media. In the referenced intrusion chain, MoonWalk is loaded in memory by the DodgeBox loader via DLL sideloading, including use of a legitimate executable such as taskhost.exe and an encrypted DAT file (sbiedll.dat) that is decrypted to produce the MoonWalk payload. The malware is described as sharing evasion techniques with DodgeBox, and the broader chain uses reflective loading and memory-only execution. MoonWalk functions as a backdoor that enables remote command execution through cmd.exe and uses a reverse shell over an unencrypted TCP connection via the Windows Winsock API. It also attempts persistence by creating a Run key at HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run with the value name MoonWalkBackdoor pointing to C:\Windows\System32\payload.dll. The content further states that MoonWalk uses Google Drive for command-and-control communication, with C2 and data exfiltration hidden in legitimate-looking Google Drive API traffic through an attacker-controlled Google Drive account, including use of a BEAR-C2 Google Drive API-based profile.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the attack chain starts with the in-memory execution of MoonWalk backdoor. Once the MoonWalk backdoor is successfully loaded by DodgeBox, the malware decrypts and reflectively loads two embedded plugins (C2 and Utility).
9 distinct techniques documented for this family, organized by ATT&CK tactic.
It dynamically resolves API functions using obfuscated hashes to evade detection... It employs FNV-1a hashing to obscure strings like DLL and function names.
The C2 plugin uses a custom encrypted C2 protocol to communicate with the attacker-controlled Google Drive account... The attackers used the Google Drive C2 (Command and Control) API as a means to establish a communication channel.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used in the APT41 intrusion chain. It is loaded by DodgeBox, supports plugin-based functionality, communicates via a custom encrypted C2 protocol over Google Drive, and is described as enabling reverse shell access and persistence via a Run registry key.
A malware family used by APT41, leveraging DLL sideloading for evasion and persistence.
Backdoor malware delivered by DodgeBox, using Google Drive for C2 and advanced evasion techniques, attributed to APT41.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.