REF3927, also referred to as RudePanda, is a Chinese-speaking intrusion cluster associated with opportunistic compromise of internet-exposed Microsoft IIS and ASP.NET servers through abuse of publicly disclosed or reused ASP.NET machine keys. The actor has been observed using ViewState deserialization for initial code execution on misconfigured servers, then deploying webshells including a Godzilla-derived framework, attempting account creation, and using legitimate remote management software to retain access. Post-exploitation activity has included attempted credential dumping with Mimikatz and attempted deployment of a modified open-source Windows kernel rootkit, internally tracked as HIDDENDRIVER with a companion userland controller, to hide processes, files, and registry artifacts and protect malicious activity from inspection. REF3927’s apparent primary monetization objective is deployment of the TOLLBOOTH IIS backdoor module. TOLLBOOTH supports SEO cloaking, selective content delivery, remote configuration retrieval, and embedded webshell functionality. Multiple variants have been observed, including native and .NET implementations and both 32-bit and 64-bit builds. The actor’s victimology appears broad and largely untargeted, consistent with automated scanning for machine-key reuse rather than sector-specific espionage collection. Identified infections were globally distributed, with reporting noting a conspicuous absence of victims located in mainland China, suggesting geofencing or operator exclusion rules. REF3927 has also been observed in some of the same victim environments as the China-aligned Ink Dragon cluster, but available reporting indicates no confirmed operational linkage beyond possible overlap in initial access methods against IIS and related web infrastructure. The actor’s tradecraft demonstrates initial access, persistence, credential theft, defense evasion, and post-exploitation capability, with activity most consistent with financially motivated server compromise and abuse rather than classic state-directed espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Separate intrusion cluster observed in some of the same victim environments as Jewelbug/Ink Dragon; assessed not operationally linked, but likely leveraging similar initial access methods to gain footholds.
Chinese-speaking cluster abusing publicly disclosed ASP.NET machine keys on misconfigured IIS servers to deploy the TOLLBOOTH backdoor/SEO cloaking modules, with follow-on web shell/RAT/credential theft and rootkit deployment.
Opportunistic, large-scale post-exploitation of misconfigured Windows IIS/ASP.NET servers reusing publicly exposed machine keys, leveraging ViewState deserialization for initial access, then deploying webshells (Godzilla fork), RMM (GotoHTTP), credential dumping attempts (Mimikatz), a modified 'Hidden' rootkit (HIDDENDRIVER/HIDDENCLI) for stealth, and an IIS backdoor module (TOLLBOOTH) primarily for SEO cloaking/link-farming monetization plus webshell/management endpoints.
Compromises IIS servers by abusing publicly disclosed ASP.NET machine keys, then deploys TOLLBOOTH modules for SEO cloaking at global scale.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.