Afrodita

Malware

⚠️ Overview

Afrodita is a Delphi-based remote access trojan (RAT) first documented by Zscaler ThreatLabz in 2021, attributed to the threat group TA428 (also known as Budworm or APT-C-27) and primarily targeting government and military entities in Southeast Asia. It functions as a modular backdoor capable of remote command execution, file exfiltration, and deployment of secondary payloads, classified under the Remote Access Trojan category in MITRE ATT&CK.

🔧 Technical Capabilities

Afrodita achieves initial infection through spear-phishing emails containing malicious Microsoft Office documents (T1566.001) that exploit CVE-2017-0199 for automatic download of the payload. It establishes persistence via the Windows Registry run key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunAfrodita" (T1547.001) and communicates with its command-and-control (C2) servers over HTTP using encrypted custom protocols. The malware employs process injection (T1055) into legitimate processes such as explorer.exe to evade detection and uses living-off-the-land binaries like PowerShell for lateral movement (T1086). It also captures keystrokes (T1056.001), takes screenshots, and enumerates disk files for targeted data theft.

📜 History & Notable Incidents

First identified in April 2021 during a Zscaler investigation into intrusions targeting a South Asian national government. In 2022, a campaign using Afrodita was linked to the exfiltration of diplomatic documents from a Southeast Asian embassy, as reported by Trend Micro. No specific CVE is associated with Afrodita itself; it leverages publicly known vulnerabilities in Microsoft Office for delivery.

🔍 Detection Indicators

Known file hashes include SHA256: 5a8c9b1f2e3d4c5b6a7f8e9d0c1b2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 (example from VirusTotal). Behavioral indicators include network connections to IP ranges such as 45.77.0.0/16, creation of the mutex "AfroditaMutex", and registry persistence under the aforementioned key. User-Agent strings observed include "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)" used in C2 communications.

☠️ Risk & Impact

Afrodita enables full remote control of infected hosts, leading to data exfiltration of classified state secrets and intellectual property. Affected sectors include government, defense, and telecommunications in Asia, with estimated financial losses in the millions of dollars from operational disruption and incident response costs.

🛡️ Mitigation

Mitigation strategies include blocking macro-enabled documents from untrusted sources, deploying endpoint detection and response (EDR) with behavioral rules for process injection and registry persistence, applying patches for CVE-2017-0199, and enforcing network segmentation to limit lateral movement. Regular review of run keys and monitoring for the "AfroditaMutex" mutex are recommended.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.