SysUpdate, also known as Soldier, is a modular cyberespionage backdoor maintained by APT27, the Chinese state-sponsored threat group also known as Iron Tiger, LuckyMouse, and Emissary Panda. It supports Windows and Linux and provides persistent remote access, command execution, file management and transfer, process enumeration and termination, service enumeration and control, and screenshot capture. It collects host and account information and can exfiltrate data through its command-and-control channel.
Windows variants use multistage loading chains that abuse legitimate signed executables through DLL side-loading. Encoded payloads are decompressed and executed in memory, with process hollowing used to launch subsequent stages. Persistence is established through registry-based startup entries or Windows services, depending on privileges. SysUpdate can conceal files using hidden attributes, store configuration in the registry, and execute commands through Windows Management Instrumentation. Linux variants are C++ ELF binaries that share functionality, encryption keys, and the ASIO networking library with Windows variants; they support daemonization and persistence through systemd services.
Updates observed in 2022 added Linux support and DNS TXT-based command-and-control communication. Variants encrypt host information using DES-based schemes, and some versions encode command-and-control traffic with Base64. Operational use includes a confirmed compromise of a gambling company in the Philippines and an attempted installation on a Middle Eastern government email server following exploitation of Microsoft Exchange ProxyLogon vulnerabilities. The initial infection vector for the investigated 2022 campaign was not established.
SysUpdate is distinct from the unrelated Soldier implants associated with Mint Sandstorm and Hacking Team.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
These intrusions exploited the Microsoft SharePoint vulnerability CVE-2019-0604 to install web shells and FOCUSFJORD payloads... UNC215 often uses FOCUSFJORD for the initial stages of an intrusion, and then later deploys HYPERBRO... | "These intrusions exploited the Microsoft SharePoint vulnerability CVE-2019-0604 to install web shells and FOCUSFJORD payloads at targets in the Middle East and Central Asia."
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Finally, they attempted to install their SysUpdate (a.k.a. Soldier) modular backdoor."
Soldier is a multistage .NET backdoor with the ability to download and run additional tools and uninstall itself. Like Drokbk, Soldier C2 infrastructure is stored on a domain rotator on a GitHub repository operated by Mint Sandstorm.
Soldier is a multistage .NET backdoor with the ability to download and run additional tools and uninstall itself. Like Drokbk, Soldier C2 infrastructure is stored on a domain rotator on a GitHub repository operated by Mint Sandstorm.
SysUpdate Modular backdoor used by APT27 for persistence, command execution, file and process management, screenshot capture, and C2 communications; supports Windows and Linux.
These intrusions exploited the Microsoft SharePoint vulnerability CVE-2019-0604 to install web shells and FOCUSFJORD payloads... UNC215 often uses FOCUSFJORD for the initial stages of an intrusion, and then later deploys HYPERBRO...
31 distinct techniques documented for this family, organized by ATT&CK tactic.
119 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux-targeting malware/backdoor that disguises itself as a legitimate system service, performs host reconnaissance (e.g., runs the GNU/Linux id command), and establishes encrypted C2 communications across multiple protocols using complex cryptographic routines.
Iron Tiger's custom malware provides command execution, file transfers and management, process and service management, screenshots, and host-information collection. The updated Windows version uses DLL sideloading, encoded shellcode, and process hollowing; Linux variants support systemd persistence. Some samples communicate through DNS TXT records. Configuration and collected host information are encrypted with DES. The earliest updated Windows sample was uploaded on July 20, 2022, and the earliest Linux sample on October 24, 2022; these are not established first-discovery dates for the family.
... SysUpdate ... (v1.2→v1.3) ...
SysUpdate (v1.2→v1.3)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.