Sysget, also known as HelloBridge, is a Windows backdoor associated with the DragonOK espionage group and used in targeted intrusions, particularly against organizations in Japan. Reported targeting has included manufacturing, high-technology, higher education, energy, and semiconductor entities, with additional lure themes suggesting interest in victims connected to Taiwan, Tibet, and Russia.
Sysget has been delivered through phishing emails carrying disguised malicious executables and through malicious RTF documents exploiting CVE-2015-1641 in Microsoft Office. Operators commonly used decoy documents and misleading file icons to induce execution. In observed campaigns, Sysget functioned as an initial foothold payload that established persistence, contacted command-and-control infrastructure over HTTP, and enabled follow-on deployment of additional malware families used by DragonOK, including PlugX, PoisonIvy, NewCT, NFlog, and FormerFirstRAT.
Across documented variants, Sysget supports remote command execution, file upload, and file download. It uses single-instance controls, persists through Windows autorun mechanisms, and in later versions adopted stronger encryption for configuration and network traffic, including a shift from RC4 to AES-128. Newer variants also introduced anti-debugging and anti-virtual-machine checks, encrypted or obfuscated network URIs, and other refinements intended to hinder analysis and detection. Some versions retrieve configuration material from the command-and-control server when local configuration is absent. Reported installation behavior includes copying itself to user-accessible startup or temporary locations and using command shell execution to create persistence entries.
Sysget is best characterized as a modular first-stage backdoor within DragonOK operations, combining social-engineering delivery, persistence, encrypted command-and-control, and basic remote administration capabilities to support longer-term espionage activity on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Sysget malware was delivered both directly via phishing emails, as well as in Rich Text Format (RTF) documents exploiting the CVE-2015-1641 vulnerability (patched in MS15-033) that in turn leveraged a very unique shellcode. | Multiple new variants of the previously discussed sysget malware family have been observed in use by DragonOK. Sysget malware was delivered both directly via phishing emails, as well as in Rich Text Format (RTF) documents exploiting the CVE-2015-1641 vulnerability.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This campaign involved five separate phishing attacks, each carrying a different variant of Sysget malware, also known as HelloBridge.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The remote server can also send the following example response. This response will instruct the malware to execute the given command.
It then spawns a new instance of 'C:\windows\system32\cmd.exe' with a window name of 'Chrome-Update'... and then proceeds to send the following command to this executable.
The ROR7 operation is a very common technique in shellcode to obfuscate what functions are being called. The author added the XOR operation to add another layer of obfuscation. ... all HTTP URIs in this version of sysget are encrypted.
図6は、PIPXが使用する一部の特徴的な通信先を元に、Maltegoで関連する要素をマッピングしたものです。通信先であるC2サーバのドメイン登録者のメールアドレスは...
96 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DragonOKが利用するマルウェアの1つ。PIPXの通信先インフラとの重複から関連付けられており、日本では少なくとも2014年ごろから利用され、2017年11月下旬の標的型攻撃でも使用が確認された。本文ではSysget v4の亜種に相当するとされる。
A DragonOK-associated backdoor/Trojan family delivered via phishing attachments and malicious RTF exploit documents. The variants provide persistence, retrieve configuration from C2, encrypt communications, execute commands, upload/download files, and include newer anti-debug/anti-VM and URI obfuscation features.
A first-stage phishing-delivered malware used as a downloader/backdoor. It drops files, establishes persistence via a Run registry key, contacts a C2 over HTTP, decrypts tasking with RC4, and can download files, upload files, and execute commands.
A first-stage payload delivered via phishing attachments. It drops files, establishes persistence via a Run key, contacts a C2 server over HTTP, retrieves an RC4 key, and can download files, upload files, and execute commands indirectly through cmd.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.