Zapoa is a previously undocumented .NET backdoor first identified by Unit 42 during investigation of intrusion cluster CL-STA-0045. It was observed in a long-running espionage campaign targeting a Southeast Asian government, including governmental entities such as critical infrastructure, public healthcare institutions, public financial administrators, and ministries. Unit 42 attributed CL-STA-0045 with moderate confidence to Alloy Taurus (also known as GALLIUM/Softcell), assessed as operating in support of Chinese state interests.
In the observed intrusions, the attackers primarily gained initial access by exploiting Microsoft Exchange Server vulnerabilities and deploying web shells, including China Chopper, on internet-facing servers. After post-exploitation activity and failed execution of another .NET backdoor (ReShell), the attackers attempted to execute Zapoa.
Zapoa opened an HTTP listener with the UrlPrefix https://*:443/256509101/ and used the string P88smzTpVBDjwiUv in HTTP POST data to authenticate command-and-control requests. Reported capabilities included system information collection, shellcode execution, process execution, file system manipulation, file timestamp modification, and loading additional .NET assemblies. Zapoa was part of a broader toolset in CL-STA-0045 that also included ReShell, GhostCringe, Quasar RAT, Cobalt Strike, Kerbrute, and China Chopper, alongside extensive credential theft, persistence, and lateral movement activity.
High-confidence indicators directly associated with Zapoa in the provided content are the HTTP listener path /256509101/ over HTTPS on port 443 and the authentication string P88smzTpVBDjwiUv used in POST data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"The attackers tried to execute another undocumented .NET backdoor, which we call Zapoa."
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously unknown backdoor (per Unit 42) used to establish/maintain access and persistence in the described espionage cluster.
.NET backdoor that opens an HTTPS listener (UrlPrefix https://*:443/256509101/) and authenticates via a specific POST string; supports system info collection, shellcode execution, process and filesystem operations, timestomping, and loading additional .NET assemblies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.