Attackers used spear-phishing emails with TinyURL links and an actor-controlled redirection server to deliver the 9002 Trojan from a Google Drive-hosted ZIP archive. The redirection chain embedded a target email address and destination URL in base64-encoded parameters, apparently to track victim clicks, and one lure targeted a legitimate Myanmar politician and human rights activist. The downloaded executable posed as a PowerPoint file, displayed a Myanmar-related conference decoy, and installed malware through DLL sideloading by abusing a legitimate RealNetworks executable.
Researchers linked the campaign’s infrastructure and beaconing artifacts to broader activity associated with Poison Ivy, PlugX, Zupdax, HenBox, and the later-identified Farseer malware family. Farseer shared tradecraft including DLL sideloading with signed binaries, encrypted and compressed payloads, obfuscated configuration data, registry persistence, and command-and-control over domains such as update.tcpdo[.]net, honor2020[.]ga, and up.outhmail[.]com. The overlapping infrastructure and Myanmar- and Southeast Asia-themed lures indicate a sustained intrusion set focused on targets in Myanmar, Taiwan, and the wider region.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Unit 42 observed more than 30 unique Farseer samples over roughly two and a half years, with most appearing in 2017 and a smaller number in 2018. The malware family used DLL sideloading, encrypted payload components, and registry-based persistence.
The Farseer report states that Poison Ivy samples had used tcpdo[.]net as command-and-control infrastructure, with activity dating back to mid-2015. This established historical infrastructure overlap later used to connect Farseer with Poison Ivy-linked operations.
Palo Alto Networks Unit 42 identified a previously unknown Windows backdoor family and named it Farseer based on a string found in an embedded PDB path. The report linked Farseer through overlapping infrastructure and tradecraft to HenBox, Poison Ivy, Zupdax, PlugX, and 9002-related activity.
Unit 42 reported a spear-phishing campaign that used TinyURL links, an actor-controlled redirector, and a Google Drive-hosted ZIP archive to deliver the 9002 Trojan. The campaign targeted at least one legitimate Myanmar politician and human rights activist and used DLL sideloading with a signed RealNetworks executable for execution.
The 9002 dropper opened a decoy PowerPoint presentation about a Myanmar conference titled "Role of JMVTI Aung San and Building of Clean and Safe Automobile Society." The presentation concerned a conference scheduled for July 30, 2016, showing the lure theme used against targets.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 113 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.