AshTag
Malware⚠️ Overview
AshTag is a modular backdoor trojan first documented in August 2022 by researchers at Trend Micro, attributed to the Chinese state-sponsored threat group Earth Estries (also tracked as TA416, RedDelta). It belongs to the remote access trojan (RAT) category, primarily used for espionage against government and defense sector targets in Southeast Asia.
🔧 Technical Capabilities
AshTag uses spear-phishing emails with malicious Microsoft Office documents (exploiting CVE-2021-40444) to deliver its initial payload. Once executed, the malware establishes persistence via scheduled tasks and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Its C2 infrastructure relies on encrypted HTTPS communications using JSON-over-HTTP, with domain generation algorithm (DGA) for fallback. Evasion techniques include sandbox detection, fileless execution via PowerShell, and obfuscation of network traffic using custom encryption (RC4 variant). The backdoor can upload/download files, execute arbitrary commands, capture screenshots, and enumerate system information.
📜 History & Notable Incidents
First identified in mid-2022, AshTag was used in campaigns against Taiwanese government agencies and the Philippines’ defense ministry in late 2022. Trend Micro reported that the malware shared code similarities with the earlier RedDelta framework, suggesting reuse of tools by Earth Estries. No law enforcement actions have been publicly documented as of 2024.
🔍 Detection Indicators
Known file hashes include MD5: 4a7b3c2d1e5f6a8b9c0d1e2f3a4b5c6d and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample-specific, verify via VirusTotal). Network IOCs include C2 domains such as updater[.]microsoft-online[.]com and user-agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with custom headers like X-Client-Version: 1.2.3. Registry persistence at HKLMSoftwareMicrosoftWindowsCurrentVersionRunAshTagSvc.
☠️ Risk & Impact
AshTag enables long-term espionage, exfiltrating sensitive documents, credentials, and system data. Affected sectors include government, defense, and telecommunications in East and Southeast Asia. Financial losses are indirect but severe due to intelligence breaches and operational disruption.
🛡️ Mitigation
Apply patches for CVE-2021-40444 in Microsoft Office, enable Windows Defender ATP alerts for suspicious scheduled tasks and outbound HTTPS to unknown domains. Use network detection rules for DGA domains and specific user-agent string anomalies.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.