Emdivi is a Windows HTTP backdoor used in targeted cyber-espionage operations against Japanese organizations. It has been closely associated with the Blue Termite threat actor, also referred to as Cloudy Omega, and was active in campaigns targeting government agencies, local governments, universities, financial institutions, energy, media, healthcare, manufacturing, transportation, and other sectors in Japan. Emdivi was notably deployed in attacks exploiting vulnerabilities in Japanese software such as Ichitaro, and later appeared in watering-hole and drive-by compromise chains using Adobe Flash exploitation.
The malware family is versioned in a structured manner, with observed variants including t17, t19, and t20. Emdivi t17 served as an infection-stage backdoor, while later tailored t20 variants provided a substantially expanded command set for post-compromise operations. Reported samples ranged from a small set of backdoor commands in earlier variants to dozens of commands in later ones, indicating ongoing development and operational refinement.
Emdivi communicates over HTTP and stores key configuration elements in encrypted form. Protected data has included command-and-control settings, API names, anti-analysis strings, mutex values, command identifiers, and proxy configuration. Some variants derived decryption material from the victim system’s Security Identifier, effectively binding the implant to an intended host and complicating analysis and reuse. Later samples added stronger cryptographic protections, including AES, to further hinder reverse engineering.
Observed delivery vectors include spearphishing with exploit documents targeting Ichitaro vulnerabilities, as well as watering-hole and drive-by-download attacks that delivered Emdivi through browser or plugin exploitation. In the Blue Termite intrusion chain, Emdivi functioned as a backdoor after initial compromise and supported sustained access to victim environments. Its use in highly tailored Japan-focused espionage activity, together with victim-specific configuration such as internal proxy settings, indicates deliberate customization for enterprise environments and long-term intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2014-7247 was exploited as a zero-day vulnerability. The attack was carried out through targeted emails which were distributed to government agencies and enterprises in Japan. | Emdivi is a bot that communicates via HTTP protocol. The malware versions are managed systematically by the developer, and there are occasional functional updates.
In 2013, a compromised website was found embedded with a Java Applet which leverages a Java vulnerability (CVE-2011-3544), resulting in Emdivi being downloaded to visitors’ devices. | Emdivi is a bot that communicates via HTTP protocol. The malware versions are managed systematically by the developer, and there are occasional functional updates.
The extracted executable file is “emdivi t17”, a new infection vector used by the attackers... Kaspersky Lab detected the tailored malware, “emdivi t20”. This malware is basically used after the infection by emdivi t17 that serves as a backdoor.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Emdivi is a bot that communicates via HTTP protocol. The malware versions are managed systematically by the developer, and there are occasional functional updates.
Emdivi is a bot that communicates via HTTP protocol. The malware versions are managed systematically by the developer, and there are occasional functional updates.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
BRONZE BUTLER used watering hole attacks (e.g. Adobe Flash Player zero-day exploit) as its main attack method until 2016... | In 2013, a compromised website was found embedded with a Java Applet which leverages a Java vulnerability (CVE-2011-3544), resulting in Emdivi being downloaded to visitors’ devices (a drive-by download attack).
they copied malware to other devices and registered the task to execute it... Other commands used were ‘at’ and ‘schtacks’ to register tasks
The Sanshiro series contains a vulnerability that allows arbitrary code execution (CVE-2014-0810)... This vulnerability was leveraged to embed shellcode in the Sanshiro document. In the case of the APT attack, the shellcode was then executed through the exploit.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor compared with ChChes. Both are described as second-stage payloads that use the victim system’s SID as an encryption key so they execute only on the intended machine.
Emdivi is a backdoor malware family used in the Blue Termite campaign against Japanese organizations. The t17 variant is delivered via spear-phishing and drive-by-download/Flash exploit and serves as an initial backdoor. The t20 variant is a more sophisticated tailored backdoor with many more commands, encrypted configuration data, hardcoded internal proxy settings, and in some samples decryption tied to the victim SID to restrict execution and hinder analysis.
Emdivi is an HTTP bot/backdoor used in campaigns targeting Japan. It supports file upload/download, event log deletion, and more advanced command sets in later versions, and was used for initial intrusion and persistence/lateral activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.