SecBox is a customized Go-based remote-access and network-pivot implant associated with an intrusion campaign tracked as Nie, a Chinese-speaking operator. It was deployed in compromises of internet-facing enterprise applications, including a Fengtai District government Office Automation environment, where ASPX webshells and downloaders installed the implant for additional endpoint control. SecBox supports remote command execution, file transfer, host discovery, port scanning, SOCKS5 proxying, port forwarding, and alternate command-and-control routing. Its communications support multiple transports, including TCP, TLS, WebSocket, KCP, and QUIC, with multiplexing for concurrent channels. SecBox can retrieve replacement command-and-control routes through an encrypted dead-drop resolution mechanism and includes self-removal functionality. Windows builds were observed in the government intrusion, and Linux-compatible second-stage implants were staged through a malicious MySQL-compatible service targeting unsafe Java deserialization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Implant déployé : SecBox (Go), masqué en syscfg.exe (System Configuration Utility).
18 distinct techniques documented for this family, organized by ATT&CK tactic.
ASPX pages invoked Win32_Process.Create through WMI; launchfw.aspx executed the downloaded implant with WMI Win32_Process.Create.
Attackers used server-side command pages to run Windows commands ... cmd.aspx ... executes commands through cmd.exe /c.
The fake MySQL workflow selected serialized Java objects and included CommonsBeanutils1, CommonsCollections6, and Spring gadget-chain payloads to download a second stage. | The malicious MySQL-compatible service returned crafted data designed to trigger unsafe object processing in a vulnerable Java client, launching a platform-aware downloader on the affected host.
Webshell-launched scripts scanned the internal environment for SMB, WinRM, web, and database services, connecting the public OA system to internal servers and infrastructure.
The implant could ... use replacement command-and-control routes. IoCs include dead-drop-resolver TCP and WebSocket redirectors.
Attackers ... move[d] data through ordinary HTTP requests... SecBox [used] replacement command-and-control routes [including] TCP and WebSocket redirector[s].
The implant could ... proxy traffic, and use replacement command-and-control routes. Hunt.io traced a shared SOCKS proxy across five connected workspaces.
SecBox established long-lived C2 connections using TCP, TLS, WebSocket, KCP, or QUIC, with Yamux multiplexing tasking, file transfer, and pivot traffic.
SecBox : implant Go multiprotocole ... Dead Drop Resolver (Pastebin/GitHub Gist, AES-256-GCM).
dl_e6.aspx [is a] loader that copies e6475722.exe to C:WindowsTempv11.exe... launchfw.aspx [downloads] c22.exe as fw.exe and executes it.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom Go-based remote-access implant used after web-server compromise. It supports remote command execution, file transfer, port scanning, traffic proxying/pivoting, and resilient command-and-control through replacement and dead-drop-resolver routes.
A Go-based remote-access implant used after compromise for command execution, file transfer, port scanning, proxying/pivoting, and resilient command-and-control through replacement routes and dead-drop resolvers. Windows and Linux-compatible variants were observed.
Implant Go multiprotocole providing remote access and communications over TCP, TLS, WebSocket, KCP and QUIC. It uses Yamux multiplexing and a Dead Drop Resolver based on Pastebin or GitHub Gist protected with AES-256-GCM.
A Go-based remote-access implant deployed on compromised Windows systems, with related Linux builds. It supports multiprotocol C2 over TCP, TLS, WebSocket, KCP, or QUIC; Yamux multiplexing; remote shell execution; file transfer; download-and-execute; process, token, and service operations; host and port discovery; SOCKS5 proxying; port forwarding; bind pivots; and self-removal. It can use encrypted dead-drop-resolver data from Pastebin or GitHub Gists to rotate C2 infrastructure. No automatic persistence was confirmed in the reviewed builds.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.