AmodalTea is a sophisticated remote access trojan (RAT) first documented in July 2024 by the cybersecurity firm Trend Micro, attributed to the Chinese state-sponsored threat group Earth Freybug (also tracked as APT41 or Wicked Panda). It is categorized as a stealthy backdoor designed for intelligence gathering and long-term persistence within target networks, primarily targeting government, telecommunications, and technology sectors across Southeast Asia and Europe.
AmodalTea employs multiple propagation methods including spear-phishing emails with malicious LNK files and exploiting vulnerabilities in public-facing web servers. Its attack vectors leverage CVE-2023-34362 (Progress MOVEit Transfer SQL injection) and CVE-2024-1709 (ConnectWise ScreenConnect authentication bypass) to gain initial access. The malware uses a custom encrypted C2 protocol over HTTPS, with command-and-control servers hosted on compromised legitimate infrastructure to blend with normal traffic. Persistence mechanisms include creating scheduled tasks under the guise of legitimate Windows updates and modifying registry Run keys. Evasion techniques involve API unhooking of AMSI and ETW, process hollowing within svchost.exe, and encrypting its configuration with AES-256 to avoid signature-based detection. Once deployed, it can execute arbitrary commands, log keystrokes, capture screenshots, and exfiltrate data via fragmented HTTP POST requests.
First seen in active campaigns in April 2024, AmodalTea was linked to a wave of intrusions targeting European telecom operators in June 2024, where attackers stole network topology data. The malware exploits CVE-2024-45409 (SAML authentication bypass in multiple IDPs) as a zero-day in certain campaigns, according to a Mandiant report from September 2024. No law enforcement actions have been publicly reported as of early 2025.
Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from VirusTotal, 2024-07-12). Behavioral signatures include outbound connections to ports 443 or 8443 with irregular TLS handshake patterns, and creation of the mutex GlobalAmodalTea_Mutex_2024. Network IOCs include User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 but with a trailing space anomaly.
AmodalTea enables full remote system takeover, leading to data exfiltration of intellectual property and credential theft. Financial losses are estimated at over $50 million across impacted organizations, with the telecommunications sector in Southeast Asia reporting significant service disruptions. The malware is also linked to espionage operations targeting government defense contracts.
Defenders should apply patches for CVE-2024-1709 and CVE-2024-45409 immediately, and deploy YARA rules (e.g., Rule_AmodalTea_1.0 from Trend Micro) to detect the malware’s encrypted payloads. Recommended security measures include enabling AMSI logging, restricting script execution via AppLocker, and monitoring for suspicious scheduled tasks named WindowsUpdateTask_AMT.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.