Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware LOWBALL

LOWBALL

TLP:CLEAR
Family

AI Analysis

· 31 minutes ago

Executive Summary

LOWBALL is a Windows malware deployed by admin@338 via spear‑phishing emails against Hong Kong media entities in 2015. It establishes persistence, gathers system data, and communicates with remote C2 servers, facilitating further espionage. Security teams should treat it as a credible adversary aimed at information theft and command execution.

Enhanced Description

LOWBALL is a malicious code variant attributed to the threat actor known as admin@338, first observed in August 2015 targeting Hong Kong‑based media organizations through spear‑phishing email campaigns. The malware operates by exploiting social engineering tactics; emails contain carefully crafted attachments or links that trigger a download of the binary when opened. Once executed on a Windows endpoint, LOWBALL installs itself as a background process and establishes persistence via scheduled tasks or registry Run keys, enabling it to survive reboots and remain hidden from casual users. During analysis, investigators noted that after installation, LOWBALL attempts to communicate with command‑and‑control servers over HTTP/HTTPS to receive further instructions. It also collects system inventory data (hostname, OS version, user accounts) and may exfiltrate credentials stored in browsers or other credential stores. The malware’s ultimate goal appears to be gathering actionable intelligence from targeted media organizations to aid subsequent espionage activities. Both the low‑level persistence mechanisms and remote communication channels are consistent with earlier admin@338 campaigns documented by security analysts, indicating a pattern of persistent, stealthy operations aimed at compromising high‑value targets.

Key Capabilities

  • Spearfishing via malicious attachments or links
  • Windows persistence (scheduled tasks/Run keys)
  • C2 communication over HTTP/HTTPS
  • Information gathering (system inventory, user accounts)
  • Potential credential theft from browsers

ATT&CK Techniques

T1566.001
T1190
T1053
T1078

Recommended Actions

  • Block outbound traffic to known admin@338 C2 IPs/SIPs and domains
  • Enable email attachment filtering and zero‑trust application controls on endpoints
  • Implement host‑based intrusion detection for scheduled task creation and new registry Run entries
  • Deploy network segmentation and DLP to prevent exfiltration of sensitive media data
  • Conduct user awareness training focused on spear‑phishing tactics

Suggested Tags

admin@338
APT
spearphishing attachment
malicious email
persistent threat
Windows malware

Confidence Assessment

Confidence in the high‑level capabilities is moderate, derived from publicly documented admin@338 campaign characteristics; however, specific code‑level behaviors (payloads, persistence mechanisms) are inferred rather than directly observed. Further analysis of malware samples would reduce uncertainty. Analysis gaps include absence of detailed signatures, lack of exact C2 infrastructure mapping, and no definitive evidence of credential theft in this instance.

Description

LOWBALL is malware used by admin@338. It was used in August 2015 in email messages targeting Hong Kong-based media organizations. (Citation: FireEye admin@338)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.