Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware RedLeaves

RedLeaves

TLP:CLEAR
Family

Also known as: BUGJUICE

AI Analysis

· 3 hours ago

Executive Summary

RedLeaves is a Windows remote access trojan used by the menuPass threat actor, derived from PlugX and Trochilus components. It establishes long‑term persistence, performs privileged system discovery, and exfiltrates data through encrypted channels, enabling stealthy lateral movement within compromised networks. Immediate defensive attention is required to detect its covert C2 traffic and mitigate potential credential theft.

Enhanced Description

RedLeaves is a Windows‑based malware family that has been linked to the threat actor known as menuPass, an adversary typically credited with employing PlugX for initial access and persistence. The codebase of RedLeaves shares significant similarities with PlugX, suggesting that it was either repurposed from existing PlugX components or derived via direct code reuse. In addition, publicly available reports indicate that the developers may have used Trochilus—a low‑visibility, open‑source framework for command and control—as a foundational library, further indicating a modular construction approach common in commercial threat actor toolkits. Operationally, RedLeaves functions as a typical Remote Access Trojan (RAT). After initial compromise, it installs persistence mechanisms such as registry Run keys or scheduled tasks, then establishes covert communication with its Command‑and‑Control (C2) infrastructure. During session establishment it is capable of executing arbitrary shell commands, spawning PowerShell scripts, and leveraging native Windows utilities to enumerate network shares, map drives, and gather system credentials. Data exfiltration is performed over standard protocols (HTTP/HTTPS or SMB), making detection against generic outbound traffic more challenging. Given its pedigree—sharing code with both PlugX and Trochilus—the threat actor behind RedLeaves is likely to prioritize stealth, persistence, and agility in lateral movement within compromised networks. While documentation on specific variants remains sparse, analysts have observed frequent use of obfuscated payloads, encrypted traffic channels, and the deployment of lightweight “stages” that download additional modules for targeted data harvesting or credential dumping. The combination of open‑source toolkits and proven commercial RAT components means RedLeaves benefits from a relatively mature development pipeline. This makes it capable of adapting to defensive controls and introduces an elevated risk profile for organizations with unpatched Windows endpoints, weak network segmentation, or inadequate monitoring of outbound C2 traffic.

Key Capabilities

  • Establishes persistent registry or scheduled‑task footholds
  • Implements a covert command & control channel (HTTP/HTTPS or SMB)
  • Executes arbitrary shell and PowerShell commands for remote control
  • Enumerates system and network resources, including shares and credentials
  • Exfiltrates collected data via encrypted outbound traffic
  • Leverages code reuse from PlugX and Trochilus to facilitate modular expansion

Recommended Actions

  • Deploy and enforce an EDR solution with real‑time monitoring of new process creation, especially for suspicious RAT binaries

Confidence Assessment

The analysis is based on a limited number of authoritative reports that connect RedLeaves to menuPass and describe its relationship to PlugX and Trochilus. While the high‑level capabilities are consistent with known Remote Access Trojans and the referenced toolkits, specific binary behaviors (e.g., exact command sets or configuration parameters) remain undocumented in the public domain. Consequently confidence is moderate; further sandboxing and network traffic analysis would be required to validate the finer details.

Description

RedLeaves is a malware family used by menuPass. The code overlaps with PlugX and may be based upon the open source tool Trochilus. (Citation: PWC Cloud Hopper Technical Annex April 2017) (Citation: FireEye APT10 April 2017)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.