HyperBro is a Windows remote access trojan and in-memory backdoor closely associated with the China-linked cyberespionage group APT27, also tracked as LuckyMouse, Emissary Panda, Iron Tiger, and Budworm. It provides persistent remote access, command execution, screenshot capture, file management, and data exfiltration. It can launch applications and scripts through Windows APIs, delete specified files, and execute shellcode injected into newly created processes.
HyperBro is commonly deployed through DLL side-loading using legitimate executables, including CyberArk Viewfinity components. The malicious DLL decrypts and decompresses a payload before executing it in memory; observed loading chains use process hollowing to inject the final backdoor. Deployments have used registry-based startup persistence, and some samples have been signed with stolen code-signing certificates. HyperBro supports command-and-control communication over HTTP and HTTPS.
HyperBro has been installed following exploitation of internet-facing enterprise applications, including Microsoft Exchange ProxyLogon vulnerabilities, and distributed through compromised messaging-software supply chains involving Able Desktop and MiMi. Its use is predominantly associated with espionage and theft of sensitive organizational information. Observed targets include government bodies, defense organizations, electronics manufacturers, healthcare institutions, and German commercial enterprises, with deployments across Asia, the Middle East, Europe, and the United States.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
their report notes the attacks are representative of an increase in the use of HyperBro malware by Chinese threat groups against German targets ... APT27’s operation ... ultimately deploying HyperBro malware to exfiltrate many gigabytes of data
DEVCORE Team discovered both CVE-2021-26855 and CVE-2021-27065. The exploitation of these two vulnerabilities leads to remote code execution with SYSTEM permissions, allowing attackers to drop webshells, for instance.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
Initial access was believed to be via CVE-2019-0604, after which the actors planted multiple web shells... In April 2019 to deploy web shells on government-related SharePoint servers in the Middle East.
In March 2021, APT27 exploited Microsoft Exchange Server ProxyLogon vulnerabilities (CVE-2021-26855/-26857/-26858/-27065) affecting Microsoft Exchange Server 2013, 2016, and 2019. The group leveraged the exploit chain to gain pre-authentication remote code execution and deploy HyperBro backdoor. | HyperBro In-memory backdoor/RAT used for persistent access, command execution, and data exfiltration.
In March 2021, APT27 exploited Microsoft Exchange Server ProxyLogon vulnerabilities (CVE-2021-26855/-26857/-26858/-27065) affecting Microsoft Exchange Server 2013, 2016, and 2019. The group leveraged the exploit chain to gain pre-authentication remote code execution and deploy HyperBro backdoor. | HyperBro In-memory backdoor/RAT used for persistent access, command execution, and data exfiltration.
Although LuckyMouse has been spotted using a widely used Microsoft Office vulnerability (CVE-2017-11882) to weaponize Office documents in the past, researchers have no proofs of this technique being used in this particular attack against the data center.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Budworm’s main payload continues to be the HyperBro malware family, which is often loaded using a technique known as dynamic-link library (DLL) side-loading.
The criminals behind the attack on Able Desktop users have access to both HyperBro and Zupdax.
In addition, the group is also known to rely on the HyperBRO malware, a Remote Access Trojan (RAT).
ESET researchers discovered that chat software called Able Desktop ... was used to deliver the HyperBro backdoor (commonly used by LuckyMouse) ... In mid-2018, we observed a first occurrence of the legitimate Able Desktop application being used to download and execute HyperBro.
UNC215 often uses FOCUSFJORD for the initial stages of an intrusion, and then later deploys HYPERBRO, which has more information collection capabilities such as screen capture and keylogging.
The same benign vfhost.exe file has also been abused in activity we attribute to... TAG-67 ... to load HyperBro through a similar low-prevalence DLL search order hijacking triad.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The first activity discovered was the exploitation of a Microsoft Exchange server using ProxyLogon vulnerabilities chain... On March, 4th of 2021, APT27 exploited ProxyLogon vulnerabilities chain affecting Microsoft Exchange server to gain initial access.
In order to execute remote command, threat actors also relied on valid credentials collected in previous stages used wmic tool to execute commands on remote hosts.
Execution T1059.001 Command and Scripting Interpreter: PowerShell ... cmd.exe /Q /c powershell Add-MpPreference -ExclusionPath C:\Windows\temp
Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell ... Adversaries were wrapping their commands through calls to cmd.exe /Q /c command line.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
The pattern of compromise is to use several different means to gain access to systems [5, 6], followed by the installation of HyperBro (and/or the HyperSSL variant).
The loader will then use the process hollowing technique to inject HyperBro backdoor (Stage 3).
Defense Evasion T1036.004 Masquerading: Masquerade Task or Service
Defense Evasion T1036.005 Masquerading: Match Legitimate Name or Location ... rename it to veeamGues.exe to hide it in plain sight.
The loader will then use the process hollowing technique to inject HyperBro backdoor (Stage 3).
The article identifies “an actual C2 that belongs to APT27” by searching for URLs containing the “/api/v2/ajax” URI sequence. It also describes HyperBro C2 servers responding on TCP port 443 with HTTP 500 errors.
Starting closest to the actors, we see connections from Chinanet Backbone or Alibaba establishing tunnels to the management VPN nodes at DigitalOcean. From these, they create tunnels to operational nodes, which they use to SSH into the malware controllers.
134 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family referenced as one of several shared tools appearing across multiple Chinese APT campaigns.
Malware associated in the content with APT27/Iron Tiger. Its C2 servers are described as commonly returning HTTP 500 Internal Server Error responses with zero content on TCP/443, enabling infrastructure hunting through matching Shodan response hashes.
A backdoor associated with Iron Tiger's earlier operations. The reference discusses samples signed with a stolen Cheetah certificate and reports of attacks against companies in Germany and France to illustrate that the actor's targeting extends beyond the current campaign. Detailed malware capabilities are not provided.
HyperBro is a remote access trojan used in targeted attacks, often associated with espionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.