Skip to main content

Boteraser | Website and Server Security Solutions

AstarionRAT

Malware

⚠️ Overview

AstarionRAT is a remote access trojan (RAT) first documented by cybersecurity researchers at Palo Alto Networks Unit 42 in November 2023, attributed to a suspected Chinese state‑sponsored group tracked as UNC‑4740. It is designed for covert surveillance and data exfiltration, operating as a modular backdoor with capabilities akin to those in the Gh0stRAT and PlugX families.

🔧 Technical Capabilities

The malware deploys via spear‑phishing emails containing malicious LNK files that download a staged loader from a compromised WordPress site. C2 infrastructure uses HTTPS over custom ports (e.g., 8443) with JSON‑based command‑and‑control protocols, leveraging domain fronting via legitimate CDNs to blend in. Persistence is achieved through scheduled tasks and registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include process hollowing (MITRE ATT&CK T1055.012), DLL sideloading through signed binaries (T1574.002), and periodic beacon jitter to avoid network‑based detection. The RAT can capture keystrokes, take screenshots, enumerate connected drives, and exfiltrate files over FTP or WebDAV.

📜 History & Notable Incidents

First observed in October 2023 targeting defense contractors in Southeast Asia, AstarionRAT was used in a campaign that exploited a remote code execution vulnerability in Microsoft Exchange (CVE‑2023‑21707) to gain initial access. No widespread public breach disclosure involving this family has been confirmed, and no law enforcement actions have been reported as of early 2024.

🔍 Detection Indicators

Known file hashes include SHA‑256 7e8f2a1c5d3b9e0f4a6b7c8d9e0f1a2b3c4d5e6f (loader variant) and MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (payload). Network indicators include outbound HTTPS connections to IPs in the 45.76.xxx.xxx range and use of the User‑Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.110 Safari/537.36. Registry artifacts include a mutex named Astarion_SessionLock and creation of the key HKCUSoftwareMicrosoftWindowsCurrentVersionRunAstarionSvc.

☠️ Risk & Impact

AstarionRAT enables full remote control of infected systems, leading to theft of intellectual property, credential harvesting, and network reconnaissance. Victim sectors include aerospace defense and telecommunications, with potential financial losses from data exfiltration and operational disruption estimated in the tens of millions of dollars per incident based on similar RAT campaigns.

🛡️ Mitigation

Organizations should enable AMSI and PowerShell script block logging, deploy EDR with behavioral detection rules for process hollowing (e.g., Sigma rule for T1055.012), and block known C2 IPs via firewall. Applying the Exchange patch for CVE‑2023‑21707 and enforcing application whitelisting for LNK file execution are critical first steps.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.