National Cyber Warfare Foundation (NCWF)

UTG-Q-010


0 user ratings
2026-09-10 18:48:56
error

UTG-Q-010 is a financially motivated APT group from East
Asia that has been active since late 2022, primarily targeting the
pharmaceutical industry and cryptocurrency enthusiasts. They exploit legitimate
Windows processes, such as \"WerFault.exe,\" to sideload malicious DLLs
like \"faultrep.dll\" and employ sophisticated phishing campaigns to
deliver malware disguised as enticing content. Their recent campaigns have
involved the use of the Pupy RAT and advanced defense evasion techniques,
including in-memory execution and reflective DLL loading. UTG-Q-010\'s strategic
focus on HR departments and the cryptocurrency sector highlights their
understanding of target vulnerabilities and their ability to evade detection.

The group primarily targets the cryptocurrency, gaming, AI,
and pharmaceutical industries, focusing on HR
departments
and crypto enthusiasts to maximize
financial returns. 

Recent campaigns identified in 2024 utilize
sophisticated phishing tactics with lures disguised as
cryptocurrency events or job recruitment emails.  These attacks
deliver Pupy RAT (a Python-based Remote Access Trojan) via
malicious LNK files and DLL loaders that
employ advanced evasion techniques such as in-memory execution and reflective
DLL loading
to avoid detection. 

Naming & Attribution

UTG-Q-010 is a designation used by QiAnXin
Threat Intelligence Centre
(RedDrip Team) for a financially motivated
APT group based in East Asia.  The \"UTG-Q-XXX\"
naming convention is QiAnXin\'s internal system for classifying threat groups
identified from their enterprise endpoint telemetry that don\'t match publicly
known APT clusters. The group has been active since late 2022 and
is characterized by economically driven operations rather than state-sponsored
espionage. 

Target Sectors & Evolution

The group\'s targeting has evolved over time:



























mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Period


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Target Sector


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt .5in 6.0pt 9.0pt\">

Lure Theme


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Late 2022


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Pharmaceutical industry


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Pharma-related content


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

2023–2024


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Gaming & AI industries


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Fake game developer resumes, AI tech recruitment


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

2024


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Cryptocurrency enthusiasts


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Fictional crypto events (e.g., \"Michelin Night: Coin
Circle Friendship Feast\")



2025



Financial sector (Hong Kong)



Supply-chain attacks targeting gold trading institutions


The 2025 supply-chain campaign marked a notable escalation —
victims expanded into finance, manufacturing, and culture sectors
in Hong Kong, with the group exploiting the gold market\'s volatility to target
exchanges, banks, custodians, and investment funds. 

Attack Techniques & TTPs

The group employs a multi-stage attack chain:


  1. Initial
    Access — Phishing (T1566):
    Spear-phishing emails crafted in
    Chinese with logically structured content. Lures include:


    • Fake
      job resumes from \"major internet companies\" targeting HR
      departments
      (e.g., mso-bidi-font-family:"Microsoft JhengHei"\">陈国光- "Microsoft JhengHei"\">节-U3D.lnk, "MS Gothic";mso-bidi-font-family:"MS Gothic"\">服 "Microsoft JhengHei"\">务端- mso-bidi-font-family:"MS Gothic"\">王少 mso-bidi-font-family:"Microsoft JhengHei"\">聪简历.lnk)

    • Cryptocurrency
      event invitations

    • Watering
      hole sites on domestic forums distributing malicious APKs for
      Android 


  2. Execution
    — Malicious LNK Files (T1204.002):
    ZIP archives contain LNK files
    disguised as PDFs or documents. The LNK file\'s content is read as a byte
    array, decrypted via XOR with key 0x71, and saved
    as faultrep.dll in the Temp directory (skipping the first 12,238
    bytes to strip non-essential data). 

  3. Defense
    Evasion — DLL Sideloading:
    The group abuses WerFault.exe (Windows
    Error Reporting process) to sideload the malicious faultrep.dll,
    making the payload appear legitimate. 

  4. Defense
    Evasion — Sandbox/VM Detection:
    The loader DLL checks for:


    • Virtualization-related
      files on disk

    • Active
      internet connection

    • In-memory
      execution without disk writes

    • Reflective
      DLL loading
      to avoid traditional detection 


  5. Command
    & Control (T1071.001):
    HTTPS-based C2 channels:


    • hxxps://chemdl.ioskaishi.live/down_xia.php

    • hxxps://chemdl.gangtaolive/down_xia.php

    • 103.79.76.40:8443

    • 223.ip.ply.gg:15270

    • 156.224.22.247:443


Malware — Pupy RAT

The payload is Pupy RAT, an open-source,
cross-platform Remote Access Trojan written in Python.  Key
capabilities include:


  • Reflective
    DLL loading
    — executes code within legitimate processes without
    writing to disk

  • In-memory
    execution
    — no persistent artifacts on disk

  • Dynamic
    capability expansion
    — loads and executes remote code directly
    from memory

  • Standard
    RAT functions: keylogging, file exfiltration, remote shell access 

Impact & Victim Profile


  • Enterprise
    victims
    are predominantly gaming companies and pharmaceutical
    companies

  • Individual
    victims
    are largely cryptocurrency traders on
    residential broadband

  • No
    \"key\" (high-profile government or critical infrastructure)
    organizations were confirmed compromised in 2024

  • The
    group has been noted for retaliatory behavior — after
    QiAnXin published their initial report in May 2024, the group launched a
    low-level spear-phishing attack against QiAnXin\'s own public email
    addresses 

Indicators of Compromise (Selected)






























mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

Type


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt .5in 6.0pt 9.0pt\">

Value


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

SHA256


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

f2db556b6e0865783b1d45a7cc40d115ceb04fe2ad145df367ac6f5d8eca901d (MichelinNight.zip)


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

SHA256


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

54368d528214df1ed436e4c82a65ccaf2daf517359a1361b736faab7253e54f6 (Pupy
RAT)


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

SHA256


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

a69693dc1a62e49853ba5eb40999f24e340faf1a087e56f9a21c4622d297c861 (MichelinNight.lnk)


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

SHA256


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

a4abc9c7e3a287641856a069355b02e36226c2ab94cc0807516b86dd66fe1cf5 (faultrep.dll)


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

C2 Domain


mso-border-bottom-alt:solid #303032 .75pt;padding:6.0pt 9.0pt 6.0pt 9.0pt\">

chemdl.ioskaishi.live



C2 IP



103.79.76.40:8443


Defensive Recommendations








































  • Email
    filtering
    tuned to detect spear-phishing with LNK file
    attachments

  • EDR
    deployment
    to detect unauthorized DLL sideloading (especially
    via WerFault.exe) and in-memory execution

  • User
    training
    focused on HR and crypto-facing staff to recognize
    social engineering lures

  • Network
    monitoring
    for outbound HTTPS to known C2 domains and unusual C2
    ports (e.g., 8443)

  • Android
    hygiene
    — block installation from unknown sources, monitor for
    APK downloads from suspicious forums 






Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.