9002 is a long-running Windows remote access trojan used in multiple Chinese cyberespionage operations and historically associated with clusters including Sunshop-related activity, PKPLUG-linked operations, and reporting that overlaps with APT17 and APT27/Emissary Panda ecosystems. It has been observed in targeted intrusions since at least 2011 and has appeared alongside other espionage tooling such as PlugX, Poison Ivy, Gh0st RAT, Briba, and HyperBro.
9002 functions as a backdoor for persistent remote control of compromised systems. Documented variants beacon to preconfigured command-and-control infrastructure, support encoded communications, and in some cases mimic SSL/TLS traffic while using custom XOR-based obfuscation. Later variants have been observed operating in memory without writing the main payload to disk, including shellcode injected into legitimate Windows processes. Builder tooling has also been identified, indicating a structured development workflow and configurable generation of new samples.
Observed delivery methods include spearphishing with lure documents, strategic web compromise, and exploit-driven infection chains. Campaigns have used malicious Word documents containing embedded shortcut files that launch PowerShell downloaders, as well as exploit chains leveraging Internet Explorer and Java vulnerabilities to install 9002. Earlier reporting also tied 9002 delivery to Google Drive-hosted malware distribution. Persistence has been achieved through mechanisms such as startup shortcut placement, and execution tradecraft has included process injection.
Operational use of 9002 is consistent with intelligence collection rather than disruptive effects. It has been deployed against a wide range of sectors and geographies, including government, technology, manufacturing, NGOs, and organizations in and around Southeast Asia. The malware’s repeated appearance across related intrusion sets, shared infrastructure, and common development artifacts suggests it has been part of a broader Chinese espionage tooling ecosystem for many years.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Internet Explorer (CVE-2013-1347) exploit code pulled down a “9002” RAT from another compromised site at hk[.]sz181[.]com. This payload had an MD5 of b0ef2ab86f160aa416184c09df8388fe and connected to a command and control server at dns[.]homesvr[.]tk.
The Internet Explorer (CVE-2013-1347) exploit code pulled down a “9002” RAT from another compromised site at hk[.]sz181[.]com. This payload had an MD5 of b0ef2ab86f160aa416184c09df8388fe and connected to a command and control server at dns[.]homesvr[.]tk.
The Internet Explorer (CVE-2013-1347) exploit code pulled down a “9002” RAT from another compromised site at hk[.]sz181[.]com. This payload had an MD5 of b0ef2ab86f160aa416184c09df8388fe and connected to a command and control server at dns[.]homesvr[.]tk.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The overlap between the HenBox and 9002 malware families involves three shared C2s between several samples...
The Internet Explorer (CVE-2013-1347) exploit code pulled down a “9002” RAT from another compromised site at hk[.]sz181[.]com. This payload had an MD5 of b0ef2ab86f160aa416184c09df8388fe and connected to a command and control server at dns[.]homesvr[.]tk.
Proofpoint recently observed a targeted email campaign attempting a spearphishing attack using a Game of Thrones lure... attempted to install a “9002” remote access Trojan (RAT) historically used by state-sponsored actors.
Proofpoint recently observed a targeted email campaign attempting a spearphishing attack using a Game of Thrones lure... attempted to install a “9002” remote access Trojan (RAT) historically used by state-sponsored actors.
Tools: Sysupdate, China Chopper, OwaAuth, ZxShell, Gh0st RAT, PoisonIvy, Hunter, PlugX, Enfal, HttpBrowser, 9002, ASPXSpy, HyperBro
1 distinct technique documented for this family, organized by ATT&CK tactic.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan/backdoor family mentioned as part of the same overlapping infrastructure set tied to domains also used by Farseer-related activity.
Remote access trojan delivered via spearphishing (DOCX with embedded LNK/OLE packager) that executes PowerShell (modified Invoke-Shellcode) to download XOR/base64-obfuscated payloads, injects 9002 shellcode into a legitimate process (wabmig.exe), maintains persistence via Startup-folder LNK, and communicates with C2 over HTTP and a fake-SSL protocol while exfiltrating data.
Trojan/backdoor malware family associated with Myanmar political-themed lures and infrastructure overlaps with HenBox, Poison Ivy, and the broader PKPLUG activity.
9002 is a remote access trojan (RAT) used for persistent access and control of compromised systems, commonly deployed in targeted APT campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.