SodaMaster is a Windows backdoor and fileless remote access tool associated primarily with China-aligned espionage activity, especially operations linked to Cicada/APT10, and has also been observed in intrusions attributed to other China-aligned clusters. It has been delivered as a payload by loaders such as DESLoader and SigLoader and has also been deployed through DLL side-loading chains and shellcode injection into suspended processes. Reported intrusion chains placing SodaMaster on victim systems have included exploitation of internet-facing infrastructure such as SSL-VPN appliances and Microsoft Exchange Server, followed by post-compromise deployment of the malware.
SodaMaster is designed for post-exploitation control of compromised Windows hosts. Documented capabilities include collecting host profiling data such as username, computer name, operating system details, process identifiers, privilege context, and execution timing; enumerating running processes; querying the Windows Registry; checking for VMware-related artifacts as an anti-analysis measure in some versions; downloading and executing additional payloads; executing received data or payloads from command and control; and, in later versions, supporting functions such as screenshot capture, keylogging control, shellcode execution, DLL execution, and theft of Outlook credentials. Multiple reports describe it as memory-resident or fileless, with strong emphasis on in-memory execution and evasion.
Its command-and-control communications have used layered cryptography. Reported implementations include initial beacon data encrypted with a hardcoded RSA public key and subsequent traffic protected with RC4; other reporting also notes RSA-encrypted outbound data and RC4-encrypted communications, with version changes over time. SodaMaster has been described as capable of obfuscating or encrypting communications with its operators and of delaying execution or performing environment checks to reduce sandbox visibility.
Operational reporting places SodaMaster in long-running espionage campaigns targeting government entities, NGOs, telecoms, legal organizations, pharmaceutical organizations, think tanks, religious and charitable institutions, and Japanese enterprises and their overseas branches. The malware has been used in campaigns spanning Asia, Europe, and North America, consistent with strategic intelligence collection rather than financially motivated crime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SigLoader and SodaMaster are still used in 2021... SodaMaster Evolution... Command List of SodaMaster Version 3
SodaMaster — Aka. DelfsCake, dfls, HEAVYPOT ▪ One of DESLoader's payloads ▪ Fileless RAT ▪ Command identifiers are d, f, l and s
SodaMaster — Aka. DelfsCake, dfls, HEAVYPOT ▪ One of DESLoader's payloads ▪ Fileless RAT ▪ Command identifiers are d, f, l and s
SodaMaster is a backdoor that was documented by Kaspersky in 2021. APT10 was the first group known to have access to this backdoor but Operation FishMedley indicates that it may now be shared among multiple China-aligned APT groups.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Penetrate via internet-facing system by using vulnerabilities or stolen credentials ... The actor always intruded via Internet-facing systems ... Intrusion via VPN Devices ... Using known vulnerabilities ... Pulse Connect Secure ... FortiGate: CVE-2018-13379 ... Cisco AnyConnect: CVE-2020-3125 ... Exploiting ProxyShell vulnerability
Install malware by using Taskscheduler ... In A41APT campaign, scheduled tasks are favor to be used
なお、コマンド「d」に関しては、コマンドの受信時のデータを使用してライブラリのロードと関数アドレスの取得を行い、その関数をCall命令で呼び出します。
At Victim D, the attackers gained access to an admin console and used it to deploy implants on other machines in the local network.
Execution Flow of HUI Loader ... XOR decode & code injection ... svchost.exe
Decrypt multiple PEs and shellcodes sequentially in multiple stages. Multiple algorithms are used for decryption. Finally, the payload is executed in memory.
It is a fileless malware that is capable of multiple functions, including evading detection in a sandbox by checking for a registry key or delaying execution
FinFisher queries Registry values as part of its anti-sandbox checks.
evading detection in a sandbox by checking for a registry key or delaying execution
Following tools were found in the lateral movement stage ... Mimikatz ... secretdump.py ... Command List of SodaMaster Version 3 ... c Steals credentials of Outlook
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
It is a fileless malware that is capable of multiple functions, including evading detection in a sandbox by checking for a registry key or delaying execution
最終的に実行されるペイロード(DelfsCake)は、DLL形式で、C2サーバからデータやペイロードなどを受信して実行する機能を有します。
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor found decrypted in memory, delivered through DLL side-loading loaders that decrypt payloads and inject them into suspended svchost.exe processes. Some loaders also steal Firefox credentials and persist as Windows services.
Backdoor that can identify the username on a compromised host.
A fileless backdoor used by Cicada/APT10 for espionage operations. It can evade sandbox detection, enumerate system details, inspect running processes, download and execute additional payloads, and obfuscate/encrypt C2 traffic.
A fileless backdoor used by Cicada/APT10 that can evade sandbox detection, enumerate system details, search running processes, download and execute additional payloads, and obfuscate/encrypt C2 traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.