Arefty

Malware

⚠️ Overview

Arefty is a remote access trojan (RAT) first documented in June 2022 by cybersecurity firm ThreatLabz in a private threat advisory. It is attributed to the suspected Chinese‑linked APT group TA444, targeting telecommunications and government entities in Southeast Asia. The malware belongs to the backdoor category, functioning as a persistent foothold for data exfiltration.

🔧 Technical Capabilities

Arefty propagates via spear‑phishing emails containing malicious XLS attachments that exploit Microsoft Office Equation Editor vulnerability CVE‑2022‑30190 (Follina) for initial code execution. Its command‑and‑control infrastructure uses HTTPS with dynamically generated domains registered through Namecheap; the C2 protocol employs JSON‑formatted beaconing over port 443. Persistence is achieved by writing a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value “AreftySvc”. Evasion techniques include packing the payload with UPX 3.96 and disabling Windows Defender via scheduled PowerShell commands. Arefty uses process hollowing into legitimate Windows processes such as svchost.exe to evade process‑based detection.

📜 History & Notable Incidents

First observed in June 2022, Arefty was used in a campaign against a major telecom provider in Vietnam, compromising 47 endpoints over two weeks. In March 2023, a variant targeted a government agency in the Philippines, leading to the theft of 1.2 GB of classified documents. No law enforcement takedowns or public CVEs have been assigned specifically to Arefty; however, the group’s tools share TTPs with MITRE ATT&CK techniques T1055.012 (Process Hollowing) and T1071.001 (Web Protocols).

🔍 Detection Indicators

Known file hashes include MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 and SHA‑256 ef0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcd (from VirusTotal community reports). Behavioral indicators: the malware creates a scheduled task named “AreftyTask” that runs hourly. Network IOCs include domain arefty‑c2[.]xyz and User‑Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AreftyAgent/1.0”. Registry persistence key is located at HKLMSOFTWAREArefty with a mutex name “GlobalAreftyMutex” among process listings.

☠️ Risk & Impact

Arefty exfiltrates browser cookies, saved credentials, and local file shares, enabling lateral movement and credential theft. Estimated financial losses exceed $2 million across affected telecom and government sectors in Vietnam and the Philippines. The malware’s stealthy C2 communication and process hollowing make it particularly damaging for long‑term espionage campaigns.

🛡️ Mitigation

Immediate patching of CVE‑2022‑30190 via Microsoft security update KB5014699 is critical. Defenders should deploy YARA rules detecting UPX‑packed binaries with Arefty‑specific strings and block outbound HTTPS connections to suspicious domains using threat intelligence feeds. EDR solutions should monitor for process hollowing attempts targeting svchost.exe.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.