Elastic analyzed a spearphishing operation targeting Malaysian government officials with a malicious Word document themed around Malaysia's 2020 political crisis. The document remotely loaded a VBA template that wrote DLL payloads to disk, downloaded Logitech's legitimate LogiMailApp.exe, and exploited DLL side-loading by placing a malicious LogiMail.dll beside it for execution.
The backdoor retrieved and decrypted a second-stage implant in memory, enabling host reconnaissance, command execution, file transfers, Registry Run-key persistence, and AES-encrypted command-and-control through dynamic-DNS infrastructure. Elastic linked the activity with moderate confidence to the China-nexus APT40/Leviathan group, citing overlaps in strings, URLs, functionality, and tactics with indicators previously published by MyCERT; DLL side-loading is a widely used execution and defense-evasion technique tracked as MITRE ATT&CK T1574.001.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Elastic analyzed the campaign and assessed with moderate confidence that it was linked to the China-nexus APT40/Leviathan group, citing shared strings, URLs, implant functionality, infrastructure, and tradecraft. Elastic also published the APT_APT40_Implant_June2020 YARA rule for the identified second-stage implant.
An espionage campaign targeted Malaysian government officials using a spearphishing attachment, Bubar Parlimen.docx, themed around the Malaysian political crisis. The document loaded a remote VBA template that deployed DLL payloads and abused Logitech LogiMailApp.exe for DLL side-loading.
MyCERT issued an advisory concerning espionage activity targeting Malaysia; its samples and indicators were later found to align with activity associated with APT40/Leviathan.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourcemycert.org.my
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.