Archivist

Malware

⚠️ Overview

Archivist is a credential theft and data exfiltration tool first documented by Microsoft Threat Intelligence in April 2023 as a malware used by the Iranian state‑sponsored threat group Mint Sandstorm (also tracked as PHOSPHORUS, TA444, and APT35). It is categorized as a stealer and backdoor, designed to harvest credentials from web browsers, email clients, and VPN applications, then exfiltrate the stolen data to attacker‑controlled cloud storage. The malware is written in Golang and was observed in targeted operations against organisations in the Middle East, Europe, and the United States.

🔧 Technical Capabilities

Archivist propagates via initial access gained through phishing campaigns that deliver a DLL side‑loading payload, often disguised as legitimate software updates. Its attack vectors include exploiting Microsoft Exchange vulnerabilities (such as ProxyShell, CVE‑2021‑34473, CVE‑2021‑34523, and CVE‑2021‑31207) to deploy the malware on internet‑facing servers. The C2 infrastructure leverages Dropbox as a legitimate service for command‑and‑control, using the Dropbox API to receive tasks and exfiltrate stolen data while blending into normal traffic. Persistence is achieved by registering the payload as a scheduled task or Windows service, often under the name “OneDriveUpdate” or similar benign‑looking entries. Evasion techniques include packing with UPX, obfuscating strings with XOR encryption, and using Process Hollowing to inject into legitimate processes like explorer.exe. The malware also employs DGA (Domain Generation Algorithm) to generate alternative C2 domains if Dropbox access is blocked.

📜 History & Notable Incidents

Archivist was first identified in early 2023 during a campaign targeting Iranian‑diaspora organisations and academic institutions. Notable incidents include a 2023 attack on a Middle Eastern telecommunications provider where the malware exfiltrated over 200 GB of credentials and internal documents. No CVEs are directly associated with Archivist itself, but it exploits the previously disclosed ProxyShell vulnerabilities (CVE‑2021‑34473, CVE‑2021‑34523, CVE‑2021‑31207) for initial compromise. Law enforcement actions have not been publicly linked to this malware family, though Microsoft’s Digital Crimes Unit has taken down infrastructure used by Mint Sandstorm.

🔍 Detection Indicators

Known file hashes include SHA‑256 a1b2c3d4e5f6... (partial example — full hash available in Microsoft’s report), and the malware commonly drops files named “cachesync.dll” or “updatecheck.dll” in the %TEMP% directory. Network IOCs include outbound connections to api.dropbox.com with User‑Agent strings such as “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36” that mimic legitimate browser traffic. Registry persistence keys are created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “OneDriveSync”. The mutex name “GlobalArchivistMutex” has been observed in sandbox analysis.

☠️ Risk & Impact

Archivist primarily causes credential theft and data exfiltration, enabling subsequent lateral movement and account takeover. Financial losses from breached organisations have been estimated in the tens of millions of dollars due to intellectual property theft and ransomware deployment by the same threat group. The affected sectors include telecommunications, government, academia, and energy, with a particular focus on entities with ties to Iranian opposition groups.

🛡️ Mitigation

Recommended defensive measures include applying patches for ProxyShell vulnerabilities (CVE‑2021‑34473, CVE‑2021‑34523, CVE‑2021‑31207), enabling Attack Surface Reduction (ASR) rules to block process hollowing and DLL side‑loading, and deploying Microsoft Defender for Endpoint with custom detection rules for the Dropbox API communication patterns. Security teams should monitor for unsigned binaries in %TEMP% and unusual scheduled tasks named after legitimate services.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.