Also known as: BUGJUICE
Executive Summary
RedLeaves is a Windows remote access trojan used by the menuPass threat actor, derived from PlugX and Trochilus components. It establishes long‑term persistence, performs privileged system discovery, and exfiltrates data through encrypted channels, enabling stealthy lateral movement within compromised networks. Immediate defensive attention is required to detect its covert C2 traffic and mitigate potential credential theft.
Enhanced Description
RedLeaves is a Windows‑based malware family that has been linked to the threat actor known as menuPass, an adversary typically credited with employing PlugX for initial access and persistence. The codebase of RedLeaves shares significant similarities with PlugX, suggesting that it was either repurposed from existing PlugX components or derived via direct code reuse. In addition, publicly available reports indicate that the developers may have used Trochilus—a low‑visibility, open‑source framework for command and control—as a foundational library, further indicating a modular construction approach common in commercial threat actor toolkits. Operationally, RedLeaves functions as a typical Remote Access Trojan (RAT). After initial compromise, it installs persistence mechanisms such as registry Run keys or scheduled tasks, then establishes covert communication with its Command‑and‑Control (C2) infrastructure. During session establishment it is capable of executing arbitrary shell commands, spawning PowerShell scripts, and leveraging native Windows utilities to enumerate network shares, map drives, and gather system credentials. Data exfiltration is performed over standard protocols (HTTP/HTTPS or SMB), making detection against generic outbound traffic more challenging. Given its pedigree—sharing code with both PlugX and Trochilus—the threat actor behind RedLeaves is likely to prioritize stealth, persistence, and agility in lateral movement within compromised networks. While documentation on specific variants remains sparse, analysts have observed frequent use of obfuscated payloads, encrypted traffic channels, and the deployment of lightweight “stages” that download additional modules for targeted data harvesting or credential dumping. The combination of open‑source toolkits and proven commercial RAT components means RedLeaves benefits from a relatively mature development pipeline. This makes it capable of adapting to defensive controls and introduces an elevated risk profile for organizations with unpatched Windows endpoints, weak network segmentation, or inadequate monitoring of outbound C2 traffic.
Key Capabilities
Recommended Actions
Confidence Assessment
The analysis is based on a limited number of authoritative reports that connect RedLeaves to menuPass and describe its relationship to PlugX and Trochilus. While the high‑level capabilities are consistent with known Remote Access Trojans and the referenced toolkits, specific binary behaviors (e.g., exact command sets or configuration parameters) remain undocumented in the public domain. Consequently confidence is moderate; further sandboxing and network traffic analysis would be required to validate the finer details.
RedLeaves is a malware family used by menuPass. The code overlaps with PlugX and may be based upon the open source tool Trochilus. (Citation: PWC Cloud Hopper Technical Annex April 2017) (Citation: FireEye APT10 April 2017)