The Chinese-based APT41 malware group is suspected of using an “advanced and upgraded version” of the malware to deliver a previously undocumented backdoor called MoonWalk.

The new variant of StealthVector, also known as DUSTPAN, is codenamed DodgeBox by the Zscaler ThreatLabz team, which discovered the loader strain in April 2024.
See also: Hackers distribute USB malware via websites
“DodgeBox is a loader that triggers the loading of a new backdoor, known as MoonWalk,” security researchers Yin Hong Chang and Sudeep Singh said. “MoonWalk shares many of the evasion techniques used by DodgeBox, while also using Google Drive for command and control (C2) communication.
APT41 is the name of a state-sponsored threat actor linked to China that has been active since at least 2007 and remains prolific. The broader cybersecurity also tracks it under the names Axiom, Blackfly, Brass Typhoon (formerly Barium), Bronze Atlas, Earth Baku, HOODOO, Red Kelpie, TA415, Wicked Panda, and Winnti.
In September 2020, the US Department of Justice (DoJ) announced charges against several threat actors associated with the hacking, accusing them of breaches at over 100 companies worldwide.
"The hackers were able to steal source code, software code signing certificates, customer data and valuable business information," the DoJ said, adding that they also supported other criminal programs, including ransomware and encryption programs.
In recent years, the threat group has been linked to breaches of US government networks between May 2021 and February 2022, as well as attacks on Taiwanese media organizations, using an open-source tool known as Google Command and Control (GC2).
Read more: ERP vendor's server hacked to distribute Xctdoor backdoor
APT41's use of StealthVector was first documented by Trend Micro in August 2021. It was described as a shellcode loader written in C/C++, used to deliver the Cobalt Strike Beacon and the shell implant called ScrambleCross (also known as SideWalk).
DodgeBox is considered an improved version of StealthVector, incorporating techniques such as call stack spoofing, DLL side-loading, and the use of fake DLLs to evade detection. The malware's propagation method remains unknown.
“APT41 uses DLL sideloading to execute DodgeBox,” the researchers said. “They use a legitimate executable (taskhost.exe), signed by Sandboxie, to load a malicious DLL (sbiedll.dll).”
The fake DLL, namely DodgeBox, is a loader DLL written in C that acts as a conduit for decrypting and launching a second-stage payload, the MoonWalk backdoor.

DodgeBox's performance on APT41 stems from the similarities between DodgeBox and StealthVector, the use of DLL sideloading – a technique widely used by China-connected groups to deliver malware like PlugX – and the fact that DodgeBox samples have been submitted to VirusTotal from Thailand and Taiwan.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
"DodgeBox is a newly identified malware loader that uses multiple techniques to evade static and behavioral detection," the researchers said.
See also: Malicious advertising campaign spreads Oyster Backdoor
It offers various capabilities, such as decrypting and loading embedded DLLs, performing audits and environmental checks, and implementing cleanup procedures.
Source: thehackernews
