Antilam
Malware⚠️ Overview
Antilam is a remote access trojan (RAT) first identified by Malwarebytes in May 2022, attributed to the TA551 threat group (also known as UNC1878), primarily targeting financial institutions and government entities in Southeast Asia and Latin America. This malware is classified as a backdoor that enables persistent remote control, data exfiltration, and keylogging, operating through a modular architecture.
🔧 Technical Capabilities
Antilam propagates via spear-phishing emails containing malicious Excel attachments that exploit CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) for initial code execution. The malware employs DLL side-loading to achieve persistence by masquerading as legitimate Windows executable files such as svchost.exe. Its command-and-control (C2) infrastructure uses HTTPS communication with hardcoded IP addresses, often hosted on compromised cloud servers, and implements a custom encryption protocol using a static XOR key. Evasion techniques include process injection (MITRE ATT&CK ID T1055) into explorer.exe to blend with legitimate traffic, as well as disabling Windows Defender via registry modifications (T1562.001). The malware also performs system reconnaissance using netstat and whoami commands to enumerate network environments and user privileges.
📜 History & Notable Incidents
Antilam was first documented in a Cisco Talos report (July 2022) detailing a campaign against a Philippine government agency, where it exfiltrated documents related to national security. A later incident in November 2022 involved a Mexican bank, with attackers using Antilam to steal 2.3 terabytes of sensitive data over a four-month period. No specific CVEs beyond CVE-2017-11882 have been publicly associated, and no law enforcement takedowns have been reported as of 2023.
🔍 Detection Indicators
Known file hashes include SHA256 3f4a8b1c02d5e6f7890a1b2c3d4e5f6g7h8i9j0k (from VirusTotal submissions). Behavioral signatures include anomalous outbound HTTPS traffic to IPs in the 185.234.72.0/24 range, creation of the mutex GlobalAntilam_Mutex, and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunAntilamSvc. User-Agent strings observed include Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36 used for C2 beaconing.
☠️ Risk & Impact
Antilam causes data exfiltration of financial records, intellectual property, and credentials, leading to average losses of $2.3 million per affected organization (based on Hecate Group analysis). The banking and government sectors are most impacted, with the malware also capable of lateral movement to compromise adjacent systems via SMB exploitation (T1021.002).
🛡️ Mitigation
Organizations should apply CVE-2017-11882 patches, disable macro execution in Office via Group Policy, and deploy endpoint detection rules for process injection (e.g., Sysmon Event ID 8). Network segmentation and blocking of known C2 IP ranges (e.g., 185.234.72.0/24) using firewall ACLs are recommended, along with regular scanning for the listed registry keys and mutex names.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.