UTG-Q-010 is a financially motivated APT group from East
Asia that has been active since late 2022, primarily targeting the
pharmaceutical industry and cryptocurrency enthusiasts. They exploit legitimate
Windows processes, such as \"WerFault.exe,\" to sideload malicious DLLs
like \"faultrep.dll\" and employ sophisticated phishing campaigns to
deliver malware disguised as enticing content. Their recent campaigns have
involved the use of the Pupy RAT and advanced defense evasion techniques,
including in-memory execution and reflective DLL loading. UTG-Q-010\'s strategic
focus on HR departments and the cryptocurrency sector highlights their
understanding of target vulnerabilities and their ability to evade detection.
The group primarily targets the cryptocurrency, gaming, AI,
and pharmaceutical industries, focusing on HR
departments and crypto enthusiasts to maximize
financial returns.
Recent campaigns identified in 2024 utilize
sophisticated phishing tactics with lures disguised as
cryptocurrency events or job recruitment emails. These attacks
deliver Pupy RAT (a Python-based Remote Access Trojan) via
malicious LNK files and DLL loaders that
employ advanced evasion techniques such as in-memory execution and reflective
DLL loading to avoid detection.
Naming & Attribution
UTG-Q-010 is a designation used by QiAnXin
Threat Intelligence Centre (RedDrip Team) for a financially motivated
APT group based in East Asia. The \"UTG-Q-XXX\"
naming convention is QiAnXin\'s internal system for classifying threat groups
identified from their enterprise endpoint telemetry that don\'t match publicly
known APT clusters. The group has been active since late 2022 and
is characterized by economically driven operations rather than state-sponsored
espionage.
Target Sectors & Evolution
The group\'s targeting has evolved over time:
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Period | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Target Sector | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt .5in 6.0pt 9.0pt\"> Lure Theme |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Late 2022 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Pharmaceutical industry | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Pharma-related content |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> 2023–2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Gaming & AI industries | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Fake game developer resumes, AI tech recruitment |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> 2024 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Cryptocurrency enthusiasts | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Fictional crypto events (e.g., \"Michelin Night: Coin |
2025 | Financial sector (Hong Kong) | Supply-chain attacks targeting gold trading institutions |
The 2025 supply-chain campaign marked a notable escalation —
victims expanded into finance, manufacturing, and culture sectors
in Hong Kong, with the group exploiting the gold market\'s volatility to target
exchanges, banks, custodians, and investment funds.
Attack Techniques & TTPs
The group employs a multi-stage attack chain:
- Initial
Access — Phishing (T1566): Spear-phishing emails crafted in
Chinese with logically structured content. Lures include: - Fake
job resumes from \"major internet companies\" targeting HR
departments (e.g., mso-bidi-font-family:"Microsoft JhengHei"\">陈国光-字 "Microsoft JhengHei"\">节-U3D.lnk, "MS Gothic";mso-bidi-font-family:"MS Gothic"\">服 "Microsoft JhengHei"\">务端- mso-bidi-font-family:"MS Gothic"\">王少 mso-bidi-font-family:"Microsoft JhengHei"\">聪简历.lnk) - Cryptocurrency
event invitations - Watering
hole sites on domestic forums distributing malicious APKs for
Android - Execution
— Malicious LNK Files (T1204.002): ZIP archives contain LNK files
disguised as PDFs or documents. The LNK file\'s content is read as a byte
array, decrypted via XOR with key 0x71, and saved
as faultrep.dll in the Temp directory (skipping the first 12,238
bytes to strip non-essential data). - Defense
Evasion — DLL Sideloading: The group abuses WerFault.exe (Windows
Error Reporting process) to sideload the malicious faultrep.dll,
making the payload appear legitimate. - Defense
Evasion — Sandbox/VM Detection: The loader DLL checks for: - Virtualization-related
files on disk - Active
internet connection - In-memory
execution without disk writes - Reflective
DLL loading to avoid traditional detection - Command
& Control (T1071.001): HTTPS-based C2 channels: - hxxps://chemdl.ioskaishi.live/down_xia.php
- hxxps://chemdl.gangtaolive/down_xia.php
- 103.79.76.40:8443
- 223.ip.ply.gg:15270
- 156.224.22.247:443
Malware — Pupy RAT
The payload is Pupy RAT, an open-source,
cross-platform Remote Access Trojan written in Python. Key
capabilities include:
- Reflective
DLL loading — executes code within legitimate processes without
writing to disk - In-memory
execution — no persistent artifacts on disk - Dynamic
capability expansion — loads and executes remote code directly
from memory - Standard
RAT functions: keylogging, file exfiltration, remote shell access
Impact & Victim Profile
- Enterprise
victims are predominantly gaming companies and pharmaceutical
companies - Individual
victims are largely cryptocurrency traders on
residential broadband - No
\"key\" (high-profile government or critical infrastructure)
organizations were confirmed compromised in 2024 - The
group has been noted for retaliatory behavior — after
QiAnXin published their initial report in May 2024, the group launched a
low-level spear-phishing attack against QiAnXin\'s own public email
addresses
Indicators of Compromise (Selected)
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> Type | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt .5in 6.0pt 9.0pt\"> Value |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> SHA256 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> f2db556b6e0865783b1d45a7cc40d115ceb04fe2ad145df367ac6f5d8eca901d (MichelinNight.zip) |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> SHA256 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> 54368d528214df1ed436e4c82a65ccaf2daf517359a1361b736faab7253e54f6 (Pupy |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> SHA256 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> a69693dc1a62e49853ba5eb40999f24e340faf1a087e56f9a21c4622d297c861 (MichelinNight.lnk) |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> SHA256 | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> a4abc9c7e3a287641856a069355b02e36226c2ab94cc0807516b86dd66fe1cf5 (faultrep.dll) |
| mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> C2 Domain | mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\"> chemdl.ioskaishi.live |
C2 IP | 103.79.76.40:8443 |
Defensive Recommendations
- Email
filtering tuned to detect spear-phishing with LNK file
attachments - EDR
deployment to detect unauthorized DLL sideloading (especially
via WerFault.exe) and in-memory execution - User
training focused on HR and crypto-facing staff to recognize
social engineering lures - Network
monitoring for outbound HTTPS to known C2 domains and unusual C2
ports (e.g., 8443) - Android
hygiene — block installation from unknown sources, monitor for
APK downloads from suspicious forums
