BackConfig is a Windows malware family associated with the Hangover threat group, also tracked as Neon, Viceroy Tiger, and MONSOON. It has been used in targeted intrusions against government and military organizations in South Asia. The malware exhibits downloader and backdoor-like behavior centered on staging and repeatedly executing additional malicious payloads on compromised hosts.
BackConfig has been delivered through malicious documents containing VBA macros and through VBS-based installation routines that deploy its downloader component. On infected systems it can download and execute files using native Windows and networking APIs, including functionality consistent with retrieving remote content over HTTP and launching payloads locally. It also gathers basic host information such as the victim computer name.
For persistence, BackConfig abuses Windows Scheduled Tasks to repeatedly execute malicious payloads. It also employs multiple defense-evasion measures, including hiding files and folders from normal Windows Explorer view, storing payloads in directories made to resemble legitimate software locations, masquerading as a legitimate DHCP service binary, removing artifacts from previous infections, and identifying prior infection-related files and folders. Samples have also used custom string decryption routines and self-signed code-signing certificates crafted to imitate a legitimate software company, further complicating analysis and detection.
Overall, BackConfig is best characterized as a Windows downloader used in espionage-oriented campaigns, with persistence, payload staging, host profiling, cleanup, and masquerading features tailored for stealthy operations against high-value governmental and military targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
References : https://unit42.paloaltonetworks.com/updated-backconfig-malware-targeting-government-and-military-organizations/
Unit 42 researchers recently published on activity by the Hangover threat group (aka Neon, Viceroy Tiger, MONSOON) carrying out targeted cyberattacks deploying BackConfig malware attacks against government and military organizations in South Asia.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
"...moved from plain text code and URLs to encoded... storing encoded executables within the documents..." and "Defense Evasion: Obfuscated Files or Information (T1027)"
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware referenced in connection with Appin-linked cyberespionage activity; the content itself does not describe capabilities beyond being malware used in targeting campaigns.
Malware associated with DoNot APT and targeting government and military organizations, mentioned in the references/background.
Uses VBS to install a downloader component and malicious documents with VBA macros.
Malware that uses a custom routine to decrypt strings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.