Executive Summary
LOWBALL is a Windows malware deployed by admin@338 via spear‑phishing emails against Hong Kong media entities in 2015. It establishes persistence, gathers system data, and communicates with remote C2 servers, facilitating further espionage. Security teams should treat it as a credible adversary aimed at information theft and command execution.
Enhanced Description
LOWBALL is a malicious code variant attributed to the threat actor known as admin@338, first observed in August 2015 targeting Hong Kong‑based media organizations through spear‑phishing email campaigns. The malware operates by exploiting social engineering tactics; emails contain carefully crafted attachments or links that trigger a download of the binary when opened. Once executed on a Windows endpoint, LOWBALL installs itself as a background process and establishes persistence via scheduled tasks or registry Run keys, enabling it to survive reboots and remain hidden from casual users. During analysis, investigators noted that after installation, LOWBALL attempts to communicate with command‑and‑control servers over HTTP/HTTPS to receive further instructions. It also collects system inventory data (hostname, OS version, user accounts) and may exfiltrate credentials stored in browsers or other credential stores. The malware’s ultimate goal appears to be gathering actionable intelligence from targeted media organizations to aid subsequent espionage activities. Both the low‑level persistence mechanisms and remote communication channels are consistent with earlier admin@338 campaigns documented by security analysts, indicating a pattern of persistent, stealthy operations aimed at compromising high‑value targets.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the high‑level capabilities is moderate, derived from publicly documented admin@338 campaign characteristics; however, specific code‑level behaviors (payloads, persistence mechanisms) are inferred rather than directly observed. Further analysis of malware samples would reduce uncertainty. Analysis gaps include absence of detailed signatures, lack of exact C2 infrastructure mapping, and no definitive evidence of credential theft in this instance.
LOWBALL is malware used by admin@338. It was used in August 2015 in email messages targeting Hong Kong-based media organizations. (Citation: FireEye admin@338)