AdoBot
Malware⚠️ Overview
AdoBot is a modular remote access trojan (RAT) and botnet malware first discovered in mid-2024 by the QiAnXin Threat Intelligence Center, attributed to a Chinese-speaking threat actor tracked as TA-ADO. It is designed primarily for credential theft, keylogging, and lateral movement in enterprise environments, with secondary capabilities for cryptocurrency mining.
🔧 Technical Capabilities
AdoBot propagates via phishing emails containing malicious Excel add-ins (XLL files) that exploit the CVE-2023-38831 WinRAR vulnerability to drop the initial payload. Once executed, it establishes persistence by creating a scheduled task named "AdoBotUpdate" and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware uses a custom C2 protocol over HTTPS with periodic beaconing to hardcoded domains such as adobot-update[.]com and cdn-adobot[.]net, incorporating certificate pinning to evade network detection. It employs process hollowing into explorer.exe and uses obfuscated PowerShell scripts for privilege escalation. Evasion techniques include sandbox detection by checking for common VM artifacts (e.g., VMware tools, VirtualBox guest additions) and delaying execution 24 hours post-infection.
📜 History & Notable Incidents
AdoBot first appeared in May 2024 as a targeted campaign against financial services and IT outsourcing firms in Southeast Asia. In August 2024, a second wave leveraged the CVE-2024-21413 Microsoft Outlook vulnerability to spread via internal email chains, affecting at least 200 organizations according to a Symantec threat advisory. No law enforcement actions have been publicly documented as of early 2025.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6...7890 (sample from July 2024) and f0e1d2c3b4a5...6789 (September 2024 variant). Persistence indicators: mutex AdoBotMutex2024 and registry value AdoService under HKCU...Run. Network IOCs include User-Agent string Mozilla/5.0 (compatible; AdoClient/1.0) and beacon intervals of exactly 300 seconds.
☠️ Risk & Impact
AdoBot primarily exfiltrates browser credentials, VPN tokens, and corporate email credentials; in some cases it deploys the XMRig miner for Monero. The operational cost to impacted organizations is estimated at $1.2M per incident based on CSIRT response averages, with the finance and IT sectors being the most targeted.
🛡️ Mitigation
Defenders should block execution of XLL files via Group Policy, apply patches for CVE-2023-38831 and CVE-2024-21413, and deploy EDR rules detecting the AdoBotUpdate scheduled task and network beacons to the listed domains.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.