RedLeaves, also known as Bugjuice, is a Windows remote-access trojan associated with the China-linked cyberespionage group APT10, also known as menuPass. Observed since 2016, it has been distributed through targeted phishing emails and used in information-theft operations. Its code shares substantial similarities with the open-source Trochilus RAT and with PlugX deployment and payload-decoding routines.
RedLeaves supports arbitrary shell-command execution, file upload and download, file deletion, screenshot capture, browser username and password theft, and collection of system, drive, network-configuration, and logged-on-user information, including Remote Desktop session details. It can also operate as a proxy and change its communication settings in response to operator commands. Command-and-control communication supports HTTP, HTTPS, TCP, and a custom protocol, with RC4 encryption protecting exchanged data.
A documented deployment chain uses a legitimate signed application, a malicious loader DLL, and an encoded payload. DLL search-order hijacking causes the application to load the malicious DLL, which decodes and executes RedLeaves. The implant subsequently runs inside another process through process injection; menuPass has used process hollowing to place it in Internet Explorer. Persistence is established through a startup shortcut, with registry-based autostart entries used as a fallback.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When we tracked ChessMaster back in November, we noted that it exploited the SOAP WSDL parser vulnerability CVE-2017-8759 (patched in September 2017) within the Microsoft .NET framework to download additional malware.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RedLeaves - A malware family, whose code overlaps with PlugX and os possibly based on the open-source tool Trochilus. | Bugjuice - A backdoor that is executed by launching a benign file to hijack the search order for loading a malicious DLL into it.
We have seen different threat actors using these providers, including the ChessMaster’s RedLeaves toolkit and the Adwind cross-platform RAT.
UAT-7290 primarily leverages a Linux based malware suite but may also utilize Windows based bespoke implants such as RedLeaves ... commonly linked to China-nexus threat actors.
Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike
Some of the notable Windows implants ... include RedLeaves (aka BUGJUICE) and ShadowPad
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
67 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a malware family sharing traits with SprySOCKS.
A backdoor with significant source code overlap with SprySOCKS, built on the Trochilus codebase.
A backdoor with extensive source code overlaps with Trochilus and common traits shared with SprySOCKS.
A backdoor referenced as sharing characteristics with SprySOCKS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.