Researchers tied the long-running Comfoo remote access trojan to broader Chinese-linked cyber-espionage activity after identifying overlaps with the Luckycat campaign and related APT operations. SecureWorks reported that Comfoo had been under continuous development since at least 2006, was previously associated with the 2010 RSA breach, and used encrypted HTTP communications, rendezvous-style command-and-control, and DNS obfuscation with dynamic DNS and bogus IP resolutions to hide active infrastructure. Trend Micro separately described Luckycat as an espionage campaign active since at least 2011 that used spearphishing emails and malicious attachments exploiting vulnerabilities including CVE-2010-3333, along with Adobe Reader and Flash flaws, to compromise targets in India, Japan, and Tibetan organizations.
The combined reporting shows a broad victim set spanning government and private-sector organizations in the United States, Europe, and Asia Pacific, as well as aerospace, energy, engineering, shipping, and military research entities. SecureWorks said it monitored dozens of active Comfoo relays, observed more than 200 malware variants and 64 campaign tags, and found the Comfoo relay server lacked authentication, allowing passive monitoring of victim logins and possible relay takeover by anyone with protocol knowledge and the static XOR key. Trend Micro said Luckycat deployed TROJ_WIMMIE and VBS_WIMMIE backdoors over HTTP port 80 and shared malware or hosting infrastructure with campaigns including ShadowNet, Duojeen, Sparksrv, and Comfoo, reinforcing links between these espionage operations.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Dell SecureWorks CTU researchers Joe Stewart and Don Jackson published an analysis of Comfoo that detailed its persistence, encrypted HTTP communications, rendezvous relay architecture, DNS obfuscation, and unauthenticated relay administration weakness.
Trend Micro published details on the Luckycat campaign, stating it had been linked to about 90 attacks in Japan and India and traced elements of the operation to hackers based in China.
Trend Micro's Luckycat Redux research described the campaign's activity and noted overlaps with Comfoo through shared malware or hosting infrastructure; SecureWorks later cited this paper as briefly mentioning Comfoo.
SecureWorks CTU said it had operated passive monitoring on dozens of active Comfoo command-and-control relays since January 2012, later observing more than 200 variants and 64 campaign tags.
Trend Micro said the Luckycat cyber-espionage campaign had been active since at least June 2011, targeting Indian military research institutions, entities in Japan, and the Tibetan community through spearphishing and exploits.
SecureWorks linked Comfoo to the 2010 RSA breach, identifying the malware family as part of that intrusion.
Dell SecureWorks CTU reported that the Comfoo remote access trojan had been in continuous development since at least 2006, marking the start of the long-running malware family covered in the analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
secureworks.com
Open sourcetrendmicro.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.