Waterbear is a modular Windows backdoor associated with BlackTech, a China-linked cyberespionage group also known as BRONZE CANAL, Earth Hundun, and Palmerworm. It has been deployed against Taiwanese government agencies and used for post-compromise access and lateral movement.
Its architecture separates a loader from the main backdoor. The loader retrieves the backdoor from command-and-control infrastructure or decrypts a locally stored payload, then loads it into memory. Later versions use patched legitimate server applications as loaders, including Citrix XenApp, EMC NetWorker, HP System Management Homepage, IBM BigFix Client, and VMware Tools. Waterbear supports HTTP CONNECT tunneling for command-and-control communications.
Waterbear uses DLL side-loading and injects decrypted shellcode into Windows system services, including the Server service. It can identify processes associated with specific security products, detect security software, and query or modify the Windows Registry to facilitate malicious DLL loading. Its evasion mechanisms include RC4-encrypted payloads, Heaven’s Gate execution across 32-bit and 64-bit modes, junk-byte and legitimate-library padding around shellcode, artificially inflated binaries, and self-modifying code. It also uses indirect thread creation to execute shellcode.
In an April 2020 campaign against Taiwanese government agencies, attackers exploited DLL integrity-validation weaknesses in a trusted data loss prevention product to load Waterbear with elevated privileges. The operation also reused access and malware remaining from earlier compromises to deploy additional malicious components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE CANAL ... Tools ... Bifrose, Deuterbear, DRIGO, Flagpro, Gh0stTimes, KIVARS, PLEAD, Spiderpig, Waterbear, XBOW
Waterbear similarly employs a modular approach to its malware. A loader component executable will connect to the C&C server to download the main backdoor and load it in memory.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
Waterbear similarly employs a modular approach to its malware. A loader component executable will connect to the C&C server to download the main backdoor and load it in memory.
Last year, Waterbear captured interest in the cybersecurity industry after implementing API hooking to hide its activities by abusing security products.
To scupper analysis attempts, the Waterbear loader will also use RC4 encryption on its main payload... The size of the malware's binary was also inflated in an attempt to bypass file-based scanners.
Self Modifying Code - Waterbear... Before self-modifying After self-modifying Only the wait-for-connection function is left
Using beginthreadex() acts as a proxy and starts the new thread at threadstartex(), instead of using the address where the shellcode is located as if using CreateThread() directly | Recent Injection Technique used by APT
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
Known as 'Heaven's Gate,' the misdirection technique is used to trick Microsoft Windows operating systems into executing 64-bit code, even when declared as a 32-bit process. This, in turn, can be used to bypass security engines... some monitor/analysis systems will only apply 32-bit analysis and will fail the 64-bit part.
Last year, Waterbear captured interest in the cybersecurity industry after implementing API hooking to hide its activities by abusing security products.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Known as 'Heaven's Gate,' the misdirection technique is used to trick Microsoft Windows operating systems into executing 64-bit code, even when declared as a 32-bit process. This, in turn, can be used to bypass security engines... some monitor/analysis systems will only apply 32-bit analysis and will fail the 64-bit part.
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE CANAL threat profile.
A complex backdoor/RAT ecosystem used by Earth Hundun/BlackTech, featuring loader+downloader stages, custom (salted) RC4 and/or CryptUnprotectData-based decryption flows, extensive anti-analysis (anti-debug/anti-sandbox/AV evasion, binary padding, anti-memory scanning), and a custom C2 protocol to retrieve a next-stage RAT with broad remote administration and file/process/service/registry capabilities.
BlackTech-linked custom malware used to maintain covert access and persistence in targeted networks.
Backdoor malware that injects decrypted shellcode into the LanmanServer service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.