HyperBro is a Windows remote access trojan and in-memory backdoor associated primarily with the Chinese espionage group APT27, also tracked as LuckyMouse, Emissary Panda, Iron Tiger, TG-3390, and BRONZE UNION. It is considered an evolution of HTTPBrowser and has been in use since at least the mid-2010s. HyperBro has been deployed in long-running espionage operations against government, commercial, technology, healthcare, education, energy, and other strategic-sector targets across Europe, the Middle East, and Asia.
HyperBro is commonly executed through DLL side-loading using legitimate signed or trusted applications. Reported loader chains decrypt and decompress an embedded payload and then execute it in memory, including by injecting shellcode into a newly created process or using process hollowing. The malware is frequently described as memory-resident and designed to provide persistent remote access while reducing forensic visibility.
Its supported functionality includes remote command execution, launching applications or scripts through Windows APIs, screenshot capture, deletion of specified files, and data exfiltration. HyperBro has been used as a backdoor for sustained access to victim networks and as an operational platform during broader intrusions involving reconnaissance, credential theft by companion tooling, lateral movement, and theft of large volumes of sensitive data. In notable APT27 intrusions, HyperBro was deployed after exploitation of internet-facing enterprise software and then used to maintain command and control and support exfiltration activity.
HyperBro has also appeared in supply-chain and trojanized-software distribution operations. It was delivered through compromised or trojanized chat and messaging software, including Able Desktop and MiMi Chat-related campaigns linked to LuckyMouse or Iron Tiger. These operations show HyperBro being used alongside other implants and loaders as part of multi-stage espionage activity.
The malware is strongly linked to Chinese state-aligned cyber-espionage tradecraft, especially campaigns emphasizing stealthy persistence, trusted-binary abuse, and long-term information theft from strategically relevant organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
their report notes the attacks are representative of an increase in the use of HyperBro malware by Chinese threat groups against German targets ... APT27’s operation ... ultimately deploying HyperBro malware to exfiltrate many gigabytes of data
DEVCORE Team discovered both CVE-2021-26855 and CVE-2021-27065. The exploitation of these two vulnerabilities leads to remote code execution with SYSTEM permissions, allowing attackers to drop webshells, for instance.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
Initial access was believed to be via CVE-2019-0604, after which the actors planted multiple web shells... In April 2019 to deploy web shells on government-related SharePoint servers in the Middle East.
In March 2021, APT27 exploited Microsoft Exchange Server ProxyLogon vulnerabilities (CVE-2021-26855/-26857/-26858/-27065) affecting Microsoft Exchange Server 2013, 2016, and 2019. The group leveraged the exploit chain to gain pre-authentication remote code execution and deploy HyperBro backdoor. | HyperBro In-memory backdoor/RAT used for persistent access, command execution, and data exfiltration.
In March 2021, APT27 exploited Microsoft Exchange Server ProxyLogon vulnerabilities (CVE-2021-26855/-26857/-26858/-27065) affecting Microsoft Exchange Server 2013, 2016, and 2019. The group leveraged the exploit chain to gain pre-authentication remote code execution and deploy HyperBro backdoor. | HyperBro In-memory backdoor/RAT used for persistent access, command execution, and data exfiltration.
Although LuckyMouse has been spotted using a widely used Microsoft Office vulnerability (CVE-2017-11882) to weaponize Office documents in the past, researchers have no proofs of this technique being used in this particular attack against the data center.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In addition, the group is also known to rely on the HyperBRO malware, a Remote Access Trojan (RAT).
In addition, the group is also known to rely on the HyperBRO malware, a Remote Access Trojan (RAT).
HyperBro In-memory backdoor/RAT used for persistent access, command execution, and data exfiltration.
ESET researchers discovered that chat software called Able Desktop ... was used to deliver the HyperBro backdoor (commonly used by LuckyMouse) ... In mid-2018, we observed a first occurrence of the legitimate Able Desktop application being used to download and execute HyperBro.
UNC215 often uses FOCUSFJORD for the initial stages of an intrusion, and then later deploys HYPERBRO, which has more information collection capabilities such as screen capture and keylogging.
The same benign vfhost.exe file has also been abused in activity we attribute to... TAG-67 ... to load HyperBro through a similar low-prevalence DLL search order hijacking triad.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The first activity discovered was the exploitation of a Microsoft Exchange server using ProxyLogon vulnerabilities chain... On March, 4th of 2021, APT27 exploited ProxyLogon vulnerabilities chain affecting Microsoft Exchange server to gain initial access.
In order to execute remote command, threat actors also relied on valid credentials collected in previous stages used wmic tool to execute commands on remote hosts.
Execution T1059.001 Command and Scripting Interpreter: PowerShell ... cmd.exe /Q /c powershell Add-MpPreference -ExclusionPath C:\Windows\temp
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell ... Adversaries were wrapping their commands through calls to cmd.exe /Q /c command line.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
The pattern of compromise is to use several different means to gain access to systems [5, 6], followed by the installation of HyperBro (and/or the HyperSSL variant).
The loader will then use the process hollowing technique to inject HyperBro backdoor (Stage 3).
In some cases the attackers modified a clean installer in about 90 minutes, inserting obfuscated JavaScript into electron-main.js.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Defense Evasion T1036.004 Masquerading: Masquerade Task or Service
Defense Evasion T1036.005 Masquerading: Match Legitimate Name or Location ... rename it to veeamGues.exe to hide it in plain sight.
The loader will then use the process hollowing technique to inject HyperBro backdoor (Stage 3).
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The defendants ... conducted unauthorized intrusions into victim networks by exploiting software vulnerabilities, conducting internal reconnaissance, and deploying malware such as PlugX to establish persistent access. The indictment alleges that the group stole data from compromised networks and transferred it to servers under their control.
The group has also used backdoors with keylogging functionality, to passively capture user credentials over time.
URLs time.ntp-server.asia C&C 45.142.214.193 C&C linux.updatelive-oline.com C&C center.veryssl.org C&C https://139.180.216.65:443/api/v2/ajax C&C
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
Starting closest to the actors, we see connections from Chinanet Backbone or Alibaba establishing tunnels to the management VPN nodes at DigitalOcean. From these, they create tunnels to operational nodes, which they use to SSH into the malware controllers.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
119 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family referenced as one of several shared tools appearing across multiple Chinese APT campaigns.
HyperBro is a remote access trojan used in targeted attacks, often associated with espionage operations.
Custom in-memory backdoor/RAT used by APT27 for persistent access, command execution, credential theft support, screenshots, file and service management, shellcode injection, and data exfiltration.
Remote access trojan that injects shellcode into newly created processes and executes it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.