LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0398: HyperBro

HyperBro is a custom in-memory backdoor used by Threat Group-3390.[1][2][3]

EnterpriseS0398MalwareObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

HyperBro matters because ATT&CK describes it as a custom in-memory Windows backdoor associated with Threat Group-3390. For leaders, the key risk is not the malware name alone, but the behaviors around it: stealth through packing/encoding, process injection, DLL abuse, web-based command-and-control, tool transfer, service execution, screen capture, and cleanup. Those behaviors test whether the organization can see malicious activity that blends into normal Windows, service, memory, and web traffic.

Executive priority

Prioritize HyperBro-related coverage as a resilience and evidence question: can the SOC prove it monitors Windows execution, suspicious service activity, process injection indicators, abnormal web command-and-control, and post-compromise collection? Because no official ATT&CK detection guidance is provided for this malware object, executives should ask for behavior-based coverage mapped to the related techniques rather than relying on malware signatures or name-based blocking.

Technical view

Validate detections around the ATT&CK relationships supplied for HyperBro: System Service Discovery, Software Packing, Encrypted/Encoded File, Process Injection, File Deletion, Web Protocols for C2, Ingress Tool Transfer, Native API use, Screen Capture, Deobfuscate/Decode Files or Information, Service Execution, and DLL abuse. Since the malware is described as in-memory and Windows-based, SOC and IR teams should confirm endpoint telemetry includes process lineage, module/DLL load context, service creation or execution events, memory-oriented EDR signals, file creation/deletion, network connections over HTTP/S-like traffic, and evidence of downloaded tools or payloads.

Likely telemetry

  • Windows endpoint process creation and parent-child process relationships
  • Windows service control and service execution events
  • DLL/module load telemetry and unusual library loading context
  • EDR memory and process-injection behavioral alerts
  • File creation, modification, deletion, encoding, and unpacking/deobfuscation evidence

Detection direction

  • Use behavior-based analytics instead of relying only on HyperBro signatures, because the object identifies in-memory behavior and related obfuscation techniques.
  • Correlate service discovery followed by service execution, DLL abuse, process injection, web-protocol communications, and file cleanup on Windows hosts.
  • Tune carefully for administrative false positives: service queries, service execution, DLL loading, file deletion, and web traffic are common in normal operations.
  • Review whether encrypted, encoded, or packed files are inspected beyond static signature matching.
  • Hunt for suspicious web-protocol traffic from unusual processes or hosts, especially when paired with tool transfer or post-compromise collection behavior.

Mitigation priorities

  • Strengthen Windows endpoint visibility first: process, service, DLL/module, file, network, and EDR memory telemetry are central to the related behaviors.
  • Reduce abuse of services and DLL loading through least privilege, application control, controlled software paths, and hardened administrative workflows where feasible.
  • Improve egress monitoring and proxy logging for web-protocol command-and-control visibility.
  • Maintain incident response playbooks for in-memory malware cases, including volatile evidence preservation and rapid host isolation decisions.
  • Use ATT&CK technique coverage reviews to produce audit-ready evidence showing what is monitored, what is blocked, and what remains a known gap.
Additional notes and limits

The supplied ATT&CK object has no official detection text and no object-level tactics, so this take is driven by the official description, Windows platform field, external references, and relationships to techniques. HyperBro is associated in ATT&CK with Threat Group-3390, but local investigation should treat that as context rather than attribution.

This summary does not assert current exploitation, customer exposure, specific indicators, or guaranteed detection. The supplied fields do not provide hashes, infrastructure, detailed procedures, or official mitigations. Local telemetry quality, EDR configuration, network logging, and Windows administrative baselines are required to determine actual coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

HyperBro

HyperBro is a custom in-memory backdoor used by Threat Group-3390.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

12 rows
DomainIDNameRelationship / procedure
EnterpriseT1055Process Injection

HyperBro can run shellcode it injects into a newly created process.[1]

EnterpriseT1574.001DLLSub-technique

HyperBro has used a legitimate application to sideload a DLL to decrypt, decompress, and run a payload.[1][4]

EnterpriseT1071.001Web ProtocolsSub-technique

HyperBro has used HTTPS for C2 communications.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

HyperBro can unpack and decrypt its payload prior to execution.[5][4]

EnterpriseT1569.002Service ExecutionSub-technique

HyperBro has the ability to start and stop a specified service.[1]

EnterpriseT1007System Service Discovery

HyperBro can list all services and their configurations.[1]

EnterpriseT1113Screen Capture

HyperBro has the ability to take screenshots.[1]

EnterpriseT1027.002Software PackingSub-technique

HyperBro has the ability to pack its payload.[4]

EnterpriseT1106Native API

HyperBro has the ability to run an application (CreateProcessW) or script/file (ShellExecuteW) via API.[1]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

HyperBro can be delivered encrypted to a compromised host.[5]

EnterpriseT1105Ingress Tool Transfer

HyperBro has the ability to download additional files.[1]

EnterpriseT1070.004File DeletionSub-technique

HyperBro has the ability to delete a specified file.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0027: Threat Group-3390

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.[1] The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.[2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
c705720051cf2c94...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundlec705720051cf…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  2. [2]
    Securelist LuckyMouse June 2018

    Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018.

    Open source URL
  3. [3]
    Hacker News LuckyMouse June 2018

    Khandelwal, S. (2018, June 14). Chinese Hackers Carried Out Country-Level Watering Hole Attack. Retrieved August 18, 2018.

    Open source URL
  4. [4]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  5. [5]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  6. [6]
    Hacker News LuckyMouse June 2018

    Khandelwal, S. (2018, June 14). Chinese Hackers Carried Out Country-Level Watering Hole Attack. Retrieved August 18, 2018.

    Open source URL
  7. [7]
    Hacker News LuckyMouse June 2018

    Khandelwal, S. (2018, June 14). Chinese Hackers Carried Out Country-Level Watering Hole Attack. Retrieved August 18, 2018.

    Open source URL
  8. [8]
    HyperBro

    (Citation: Unit42 Emissary Panda May 2019)

  9. [9]
    HyperBro

    (Citation: Unit42 Emissary Panda May 2019)

  10. [10]
    HyperBro

    (Citation: Unit42 Emissary Panda May 2019)

  11. [11]
    Securelist LuckyMouse June 2018

    Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018.

    Open source URL
  12. [12]
    Securelist LuckyMouse June 2018

    Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018.

    Open source URL
  13. [13]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  14. [14]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  15. [15]
    mitre-attackS0398
    Open source URL
  16. [16]
    mitre-attackS0398
    Open source URL
  17. [17]
    mitre-attackS0398
    Open source URL
  18. [18]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  19. [19]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  20. [20]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  21. [21]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  22. [22]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  23. [23]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  24. [24]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  25. [25]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  26. [26]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  27. [27]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  28. [28]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  29. [29]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  30. [30]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  31. [31]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  32. [32]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  33. [33]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  34. [34]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  35. [35]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  36. [36]
    Hacker News LuckyMouse June 2018

    Khandelwal, S. (2018, June 14). Chinese Hackers Carried Out Country-Level Watering Hole Attack. Retrieved August 18, 2018.

    Open source URL
  37. [37]
    Hacker News LuckyMouse June 2018

    Khandelwal, S. (2018, June 14). Chinese Hackers Carried Out Country-Level Watering Hole Attack. Retrieved August 18, 2018.

    Open source URL
  38. [38]
    Securelist LuckyMouse June 2018

    Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018.

    Open source URL
  39. [39]
    Securelist LuckyMouse June 2018

    Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018.

    Open source URL
  40. [40]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  41. [41]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  42. [42]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  43. [43]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  44. [44]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  45. [45]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  46. [46]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  47. [47]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  48. [48]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  49. [49]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  50. [50]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  51. [51]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  52. [52]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.