HyperBro

MITRE ATT&CK: S0398 View on attack.mitre.org

Aliases: HyperBro

First seen
2016-09-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Operating systems
windows
Related IoCs
4
Last IoC activity
2026-07-18 21:43:36
Profile updated
2026-07-07 12:37:12

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities

Targeted regions: country_code:cn country_code:us country_code:gb

Context

HyperBro is a custom in-memory backdoor used by Threat Group-3390.

Detection coverage

  • 6 YARA rules
  • 301 Sigma rules

Malware & tools used

  • Process Injection (attack-pattern)
  • DLL (attack-pattern)
  • Web Protocols (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Service Execution (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Software Packing (attack-pattern)
  • Native API (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • File Deletion (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Hyperbro_Auto (yara-rule)
  • DITEKSHEN_MALWARE_Win_Hyperbro (yara-rule)
  • DITEKSHEN_MALWARE_Win_Hyperbro02 (yara-rule)
  • SIGNATURE_BASE_APT_RU_APT27_Hyperbro_Vftrace_Loader_Jan22_1 (yara-rule)
  • SIGNATURE_BASE_Hvs_APT27_Hyperbro_Decrypted_Stage2 (yara-rule)
  • SIGNATURE_BASE_Hvs_APT27_Hyperbro_Stage3_Persistence (yara-rule)

Reports & references

  • Kaspersky — 86083 (report)
  • secureworks.com — Bronze Union (report)
  • Trend Micro — Iron Tiger Apt Updates Toolkit With Evolved Sysupdate Malware Va (report)
  • decoded.avast.io — Apt Group Targeting Governmental Agencies In East Asia (report)
  • ESET — Luckymouse Ta428 Compromise Able Desktop (report)
  • Trend Micro — Irontiger Compromises Chat App Mimi Targets Windows Mac Linux Users (report)
  • Mandiant — Unc215 Chinese Espionage Campaign In Israel (report)
  • decoded.avast.io — Apt Group Targeting Governmental Agencies In East Asia (report)
  • Trend Micro — Operation Drbcontrol Uncovering A Cyberespionage Campaign Targeting Gambling Companies In Southeast Asia (report)
  • thehackernews.com — Chinese Watering Hole Attack (report)
  • Palo Alto Unit 42 — Emissary Panda Attacks Middle East Government Sharepoint Servers (report)
  • ptsecurity.com — Incident Response Polar Ransomware Apt27 (report)
  • web.archive.org — Summit Archive 1574947864 (report)
  • Mandiant — Chinese Espionage Tactics (report)
  • ESET — Eset Industry Report Government (report)
  • sstic.org — Sstic2020 Slides Pivoter Tel Bernard Ou Comment Monitorer Des Attaquants Ngligents Lunghi (report)
  • youtube.com — Watch (report)
  • secureworks.com — A Peek Into Bronze Unions Toolbox (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Hyperbro (report)
  • cyware.com — Apt27 Group Targets German Organizations With Hyperbro 2C43B7Cf (report)
  • intrinsec.com — Apt27 Analysis (report)
  • Trend Micro — Iocs Irontiger Compromises Chat Application Mimi Targets Windows Mac Linux Users.Txt (report)
  • blog.team-cymru.com — How The Iranian Cyber Security Agency Detects Emissary Panda Malware (report)
  • vblocalhost.com — Vb2020 Shank Piccolini (report)
  • bleepingcomputer.com — German Govt Warns Of Apt27 Hackers Backdooring Business Networks (report)

External references