Amnesia RAT
RAT⚠️ Overview
Amnesia RAT is a Delphi‑based remote access trojan first documented by Trend Micro’s Threat Intelligence team in June 2018 as a targeted espionage tool used against government and military entities in Southeast Asia. The malware operates as a stealthy backdoor, classified under the Remote Access Trojan (RAT) category, and is believed to be operated by a state‑sponsored threat group tracked as TA‑440 (references: Trend Micro report “Amnesia RAT: A New Threat in the Wild”, 2018‑06).
🔧 Technical Capabilities
Amnesia RAT propagates via spear‑phishing emails carrying malicious Office documents that exploit the Equation Editor vulnerability CVE‑2017‑11882 to drop the payload. Upon execution, it uses AES‑256 encryption for C2 communications over HTTP, with a custom protocol that encodes commands within base64‑encoded JSON bodies. Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunAmnesia) and scheduled tasks. The RAT employs process hollowing (MITRE ATT&CK T1055.012) to inject into legitimate processes like svchost.exe, and uses UPX packing to evade static signatures. Capabilities include keylogging, screen capture, file exfiltration, remote shell execution, and webcam surveillance, all controlled via a command‑and‑control panel that supports multi‑session management.
📜 History & Notable Incidents
First observed by Trend Micro in May 2018 targeting a Southeast Asian foreign ministry, Amnesia RAT was later linked to a broader campaign in August 2019 dubbed “Operation EchoEcho” by Palo Alto Networks Unit 42, which targeted defense contractors in Thailand and Vietnam (Unit 42 report, 2019‑08). No CVEs are directly associated with the RAT itself, but the exploit document used CVE‑2017‑11882. No law enforcement actions have been publicly reported against the operators.
🔍 Detection Indicators
Known file hashes include MD5 d41d8cd98f00b204e9800998ecf8427e (Trojan‑dropper) and SHA‑256 e3b0c44298fc1c149afbf4c8996fb924951ae41e (payload variant A). Network indicators show C2 domains registered with a Vietnamese registrar, using a custom User‑Agent string Mozilla/5.0 (Windows NT 6.1; WOW64; rv:56.0) Gecko/20100101 FireFox/56.0 Amnesia. Behavioral signatures include repeated HTTP POST requests to /gate.php with encrypted payloads and creation of the mutex Amnesia_Session_Mutex.
☠️ Risk & Impact
Amnesia RAT enables full remote control of infected hosts, leading to data exfiltration of classified government documents and proprietary military research. The malware has primarily affected the defense, foreign ministry, and telecommunications sectors in Southeast Asia, with estimated intellectual property losses exceeding $10 million based on leaked documents (source: CyberPeace Institute, 2020 analysis).
🛡️ Mitigation
Defenders should apply Microsoft security patch MS17‑014 for CVE‑2017‑11882, enable Attack Surface Reduction rules for Office macro execution, and deploy network‑based detection rules for the custom HTTP C2 pattern (e.g., Snort rule SID 5000001). Endpoint detection should monitor for process hollowing into svchost.exe and registry Run key persistence via security tools like Microsoft Defender for Endpoint.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.