Poison Ivy is a Windows remote access trojan and backdoor that has been widely used in espionage intrusions for many years, particularly by multiple China-linked threat groups, while also appearing in operations attributed to other actors such as MoleRATs. It has been observed in campaigns targeting government, diplomatic, defense, manufacturing, pharmaceutical, academic, and high-technology organizations, including operations focused on Japan and the Middle East.
Poison Ivy provides remote operators with interactive backdoor access to compromised systems. Documented capabilities include opening a command-line interface, stealing system information, uploading files, capturing window titles, and logging keystrokes. It can stage collected data locally prior to exfiltration and encrypt command-and-control communications with the Camellia cipher. The malware also supports process injection by injecting a malicious DLL into another process, and some variants or deployments have been associated with starting a rootkit component from disk.
Persistence and execution tradecraft associated with Poison Ivy includes creation of Registry Run entries, Active Setup persistence, registration of Windows services, and creation of device-related Registry subkeys. It has also been loaded through DLL side-loading using legitimate executables, a technique used by multiple intrusion sets to covertly execute the malware in memory and evade detection. Scheduled-task persistence has also been reported in at least some actor deployments of Poison Ivy.
Poison Ivy is commonly treated as commodity malware within targeted intrusion ecosystems rather than as tooling exclusive to a single actor. It has been reported in operations involving groups such as menuPass, GALLIUM, Soft Cell, DragonOK, and other China-linked clusters, as well as in campaigns associated with Palestinian espionage actors. Its long operational history, flexible persistence options, encrypted communications, and modular post-compromise functionality have made it a durable tool for long-term access and intelligence collection on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This DLL consists in a packed version of a PoisonIvy RAT sample, that after a few seconds makes traffic to the C2 server “95.179.131.29”, through port 443, and in case of error, through port 8080 using HTTP traffic.
[10] Jul 5 CVE-2010-2883 PDF invitation.pdf with Poison Ivy from 112.121.171.94 | pu.flower-show.org | PlugX includes config data like PoisonIvy – e.g., C2 hostname/IP/domain, installed service name/registry value
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Used a tool to exploit MS17-010 for lateral movement. Scan Tool for MS17-010: ms17-010-m4ss-sc4nn3r v1.0. Exploit Tool for MS17-010: eternalblue.py. | The RAT has long been used by Chinese APT groups ... Operation LagTime IT ... Using Royal Road RTF Weaponizer, Poison Ivy and Cotx RAT
Unit 42 observed this new Poison Ivy variant we’ve named SPIVY being deployed via weaponized documents leveraging CVE-2015-2545.
安天2017年针对“绿斑”组织的一个新的前导攻击文档进行了分析,该文档利用最新的CVE-2017-8759漏洞下载恶意代码到目标主机执行。样本采用RTF格式而非之前的宏代码方式,在无须用户交互的情况下就可以直接下载并执行远程文件,攻击效果更好。 | 该WEB服务器上存放了多个不同配置的恶意脚本和可执行文件,一个目录下是一组攻击样本,最终运行的Poison Ivy ShellCode(Poison Ivy是一个远程管理工具)都会连接一个单独C2地址。
While we were unable to recover the initial vulnerability used, it is possibly the same CVE 2014-0515 Adobe Flash exploit first reported by Cisco TRAC in late July. | All of the malware were variants of the Poison Ivy Remote Administration Tool (RAT) and were properly identified as such by our WildFire platform.
另一种是格式攻击文档,利用漏洞CVE-2012-0158来释放并执行可执行文件,同时打开欺骗收件人的“正常”文档文件。... CVE-2012-0158是一个文档格式溢出漏洞... 该组织则使用了MHT格式,这种格式同样可以触发漏洞,而且在当时一段时间内可以躲避多种杀毒软件的查杀。 | 该WEB服务器上存放了多个不同配置的恶意脚本和可执行文件,一个目录下是一组攻击样本,最终运行的Poison Ivy ShellCode(Poison Ivy是一个远程管理工具)都会连接一个单独C2地址。
The spreadsheet contained a zero-day exploit that installs a backdoor through an Adobe Flash vulnerability (CVE-2011-0609). As a side note, by now Adobe has released a patch for the zero-day, so it can no longer be used to inject malware onto patched machines. | In the case of the RSA attack the assault involved a variant of the Poison Ivy Trojan.
The second jar file had a MD5 of 3fbb7321d8610c6e2d990bb25ce34bec and exploited CVE-2013-1493. ... The jar that exploited CVE-2013-1493 dropped a 9002 RAT with a MD5 of 42bd5e7e8f74c15873ff0f4a9ce974cd. ... The exploit site at sunshop[.]com[.]tw previously hosted a different malicious jar file on April 2, 2013. This jar file had a MD5 of 51aff823274e9d12b1a9a4bbbaf8ce00. It exploited CVE-2013-1493 and dropped a Poison Ivy RAT.
China-linked actors using the exploit to deploy POISONIVY, dropped as a BAT file that downloads additional payloads.
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
27 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
[4] https://www.fireeye.com/blog/threat-research/2013/08/operation-molerats-middle-east-cyber-attacks-using-poison-ivy.html
GALLIUM established persistence for PoisonIvy by created a scheduled task.
In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group...
Soft Cell used DLL side-loading to covertly load PoisonIvy into memory on the victim machine.
Three of the backdoors, NFlog, PoisonIvy, and NewCT have previously been publicly associated with DragonOK.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
We’ve uncovered some new data and likely attribution regarding a series of APT watering hole attacks this past summer... they compromised several sites, including a well-known Uyghur website written in that native language. | Watering hole attacks offer a much better chance of success because they involve compromising legitimate websites and installing malware intended to compromise website visitors.
the APT group changed tactics and somehow compromised the update chain of NoxPlayer. A fake update package was sent to Southeast Asian gamers.
The attackers spoofed several sender email addresses to send spear phishing emails, most notably public addresses associated with the Sasakawa Peace Foundation and The White House.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
PoisonIvy creates a Registry subkey that registers a new system device.
PoisonIvy creates a Registry subkey that registers a new service. PoisonIvy also creates a Registry entry modifying the Logical Disk Manager service to point to a malicious DLL dropped to disk.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
PoisonIvy can inject a malicious DLL into a process.
PoisonIvy creates a Registry subkey that registers a new service. PoisonIvy also creates a Registry entry modifying the Logical Disk Manager service to point to a malicious DLL dropped to disk.
PoisonIvy hides any strings related to its own indicators of compromise.
Decoy documents are a common technique used by many actors to trick victims into believing they have opened legitimate files from spear phishing e-mails. The attacker sends a malicious file which infects the host with malware and then displays a clean document which contains content the victim is expecting to see.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
this new version generates a payload that has been prepended with anywhere from 1 to 16 bytes of pseudo-random data... the remainder of the protocol remains unchanged.
In summary, an individual using the name Zheng Yanbin was certainly associated with APT10 and was involved in purchasing or managing C2 infrastructure used by the group.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
Additionally, the actors have now added the popular PlugX backdoor to their toolkit. An additional backdoor appears to be a new, custom-built tool... named 'FormerFirstRAT'.
217 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
139 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware listed in Symantec protections against Elfin attacks.
Mentioned only as a non-exclusive tool that should not be used alone for APT10 attribution.
Shared frameworks such as PoisonIvy, ShadowPad, and more recently NosyDoor, have made attribution through this method increasingly difficult.
Legacy remote access trojan variant used in earlier APT-C-01 campaigns via spear-phishing and watering hole attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.