Flagpro is a Windows malware family associated with the China-linked espionage group BlackTech, also tracked as Earth Hundun, BRONZE CANAL, Palmerworm, Circuit Panda, and Red Djinn. It is used primarily in the early stages of intrusions to profile compromised hosts, assess whether a victim is of operational interest, communicate with command-and-control infrastructure over HTTP, and download and execute follow-on payloads such as BTSDoor. Reporting also describes BUSYICE as an alias or closely related designation for this malware family, characterizing it as an HTTP client implemented in C/C++ that functions as both a backdoor and downloader.
Flagpro has been observed in spearphishing campaigns targeting organizations in Japan and elsewhere in East Asia, including defense, media, telecommunications, technology, semiconductor, manufacturing, government, and professional-services environments. Delivery commonly relies on tailored phishing emails carrying password-protected archive attachments that contain malicious macro-enabled Excel documents. When a victim enables macros, the document drops the malware into the Windows Startup folder to obtain persistence and execute on reboot; some variants can also be launched immediately.
Once active, Flagpro performs reconnaissance and victim profiling by executing operating-system commands and returning the results to its operators. Documented examples include commands used to identify the current user, enumerate network configuration, and discover mapped network shares. It can repeatedly poll its command-and-control server for instructions, decode Base64-encoded tasking, save downloaded payloads to temporary storage, and execute them. Command-and-control traffic has been reported to use Internet Explorer COM functionality, including the IWebBrowser2 interface, likely to blend with normal system behavior.
Flagpro also includes credential-access functionality. Multiple analyses report that it can collect and exfiltrate credentials stored in Windows, including WinInet-saved credentials obtained from the Windows Credential Store. In addition to credential theft, it can exfiltrate command output and other collected data over its existing command-and-control channel.
A notable feature of Flagpro is user-notice suppression and targeting awareness. Variants can detect whether the environment appears Japanese-, Taiwanese-, or English-language based on specific dialog behavior, and can automatically close Windows Security and Internet Explorer dialogs to reduce the chance that users notice authentication prompts or suspicious outbound communications. Later variants reportedly added logic to interact with such dialogs more selectively. Public reporting has also described an MFC-based variant referred to as Flagpro v2.0, while earlier samples are referred to as v1.0.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE CANAL ... Tools ... Bifrose, Deuterbear, DRIGO, Flagpro, Gh0stTimes, KIVARS, PLEAD, Spiderpig, Waterbear, XBOW
2021: dropping FlagPro ... The downloader can perform C2 via the IWebBrowser2 interface and execute basic commands ... Flagpro can download and execute a backdoor.
BUSYICE (aka Flagpro) • BUSYICE is HTTP client written in C/C++, which works as both backdoor/downloader
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Open directory containing Consock, new malware Flagpro and folders of router exploits ... Exploits for known CVEs in routers, cloud platforms, and databases
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
攻撃者は最初に環境調査を行い、Flagproの動作環境が標的として適しているか調査します。適していると判断した場合、2次検体がダウンロード・実行されます。
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE CANAL threat profile.
Custom malware family cited as part of BlackTech’s toolkit for stealthy access and persistence.
Executes malicious VBA macros embedded in .xlsm files.
Backdoor malware used to execute net view to discover mapped network shares.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.