Elastic Security Labs linked the REF7707 cyberespionage activity to a modular malware ecosystem targeting a South American foreign ministry and likely victims in Southeast Asia. The operators used valid credentials and Windows administrative functionality to deploy the PATHLOADER and GUIDLOADER loaders, including a renamed cdb.exe Microsoft debugger to execute in-memory shellcode. PATHLOADER retrieved encrypted payloads from typosquatted and attacker-controlled infrastructure before launching FINALDRAFT, a Windows and Linux remote-access tool that used Microsoft Graph API access to communicate through Outlook draft messages.
FINALDRAFT supports collection and exfiltration, process injection, proxying, file operations, network discovery, in-memory PowerShell with AMSI/ETW bypasses, and Pass-the-Hash activity; samples spanning 2023 and 2024 indicate sustained development. Elastic later identified NANOREMOTE and its WMLOADER delivery component as likely related to the same cluster: WMLOADER masquerades as security software, decrypts wmsetup.log with AES-CBC, and executes the backdoor in memory, while NANOREMOTE uses the Google Drive API for command-and-control, payload staging, and bidirectional file transfer. Shared loader behavior, cryptographic material, filenames, code, and network traits indicate a common development environment or codebase.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
A wmsetup.log sample uploaded to VirusTotal from the Philippines was decrypted using WMLOADER and found to contain a FINALDRAFT implant. The artifact later provided evidence linking WMLOADER activity to the FINALDRAFT ecosystem.
Elastic Security Labs discovered the NANOREMOTE Windows backdoor in telemetry. The observed WMLOADER infection chain executed NANOREMOTE in memory and showed code, cryptographic, and loader overlaps with FINALDRAFT and REF7707.
Elastic observed the REF7707 intrusion cluster at the foreign ministry of an unnamed South American nation. The operators used valid network credentials, Windows administrative features, lateral movement, credential harvesting, and scheduled-task persistence while deploying PATHLOADER and FINALDRAFT.
Linux ELF variants of the FINALDRAFT backdoor were submitted from the United States and Brazil. The samples referenced infrastructure and services associated with the broader REF7707 activity.
GUIDLOADER sample uploads from Hong Kong continued through August 2023, showing continued development and testing of the loader family associated with FINALDRAFT.
Twelve GUIDLOADER samples were uploaded from Hong Kong, including samples with broken decryption routines and debug strings indicating development or testing. The loaders were configured to retrieve payloads from attacker infrastructure and third-party services including Firebase, Pastebin, and a Southeast Asian university storage system.
The earliest identified REF7707-related sample, a PATHLOADER variant named dwn.exe, was submitted from Thailand. It was configured to retrieve encrypted FINALDRAFT payloads from typosquatted domains impersonating Check Point and Fortinet.
Elastic published YARA rules for NANOREMOTE and WMLOADER and reported endpoint detections for related activity, including invalid signatures, cloud-service abuse, shellcode injection, and unsigned-code execution.
After registering the expired support.fortineat[.]com domain, Elastic observed characteristic TLS connections from eight telecommunications and internet-infrastructure companies in Southeast Asia, indicating possible additional REF7707 victims.
During its REF7707 investigation, Elastic Security Labs identified the previously unreported PATHLOADER loader and FINALDRAFT cross-platform backdoor toolkit. Elastic assessed the operation as likely espionage-oriented and documented FINALDRAFT's Microsoft Graph/Outlook-draft command-and-control mechanism.
Elastic Security created the Windows_Trojan_PathLoader_d62822f8 YARA rule to detect PathLoader in Windows files and memory on x86 and ARM64 systems. The rule requires three of four indicators, including a WinHttpSendRequest debug string and byte patterns associated with FNV-based API resolution and PEB access.
Elastic Security created two severity-100 YARA rules, Multi_Trojan_FinalDraft_81975d51 and Multi_Trojan_FinalDraft_69deb8cd, to detect FINALDRAFT in files and memory on x86 and ARM64 systems. The rules use distinctive Outlook draft-folder and communication-channel strings, plus binary signatures, to identify the malware.
Elastic created the severity-100 Windows_Trojan_FinalDraft_ce03cf22 YARA rule for file and memory scanning on Windows x86 and ARM64 systems. The rule detects FINALDRAFT using at least five indicators, including configuration-decryption and key-derivation sequences, injection-target strings, and Microsoft Graph refresh-token parameters.
Elastic Security created the severity-100 Linux_Trojan_FinalDraft_4ea5a204 YARA rule for file and memory scanning of Linux/x86 FINALDRAFT samples. The rule detects FINALDRAFT through communication-channel strings and multiple operational indicators, including refresh-token request and filesystem-path strings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourceelastic.co
Open sourceelastic.co
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcelolbas-project.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.