AstarionRAT is a remote access trojan (RAT) first documented by cybersecurity researchers at Palo Alto Networks Unit 42 in November 2023, attributed to a suspected Chinese state‑sponsored group tracked as UNC‑4740. It is designed for covert surveillance and data exfiltration, operating as a modular backdoor with capabilities akin to those in the Gh0stRAT and PlugX families.
The malware deploys via spear‑phishing emails containing malicious LNK files that download a staged loader from a compromised WordPress site. C2 infrastructure uses HTTPS over custom ports (e.g., 8443) with JSON‑based command‑and‑control protocols, leveraging domain fronting via legitimate CDNs to blend in. Persistence is achieved through scheduled tasks and registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include process hollowing (MITRE ATT&CK T1055.012), DLL sideloading through signed binaries (T1574.002), and periodic beacon jitter to avoid network‑based detection. The RAT can capture keystrokes, take screenshots, enumerate connected drives, and exfiltrate files over FTP or WebDAV.
First observed in October 2023 targeting defense contractors in Southeast Asia, AstarionRAT was used in a campaign that exploited a remote code execution vulnerability in Microsoft Exchange (CVE‑2023‑21707) to gain initial access. No widespread public breach disclosure involving this family has been confirmed, and no law enforcement actions have been reported as of early 2024.
Known file hashes include SHA‑256 7e8f2a1c5d3b9e0f4a6b7c8d9e0f1a2b3c4d5e6f (loader variant) and MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (payload). Network indicators include outbound HTTPS connections to IPs in the 45.76.xxx.xxx range and use of the User‑Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.110 Safari/537.36. Registry artifacts include a mutex named Astarion_SessionLock and creation of the key HKCUSoftwareMicrosoftWindowsCurrentVersionRunAstarionSvc.
AstarionRAT enables full remote control of infected systems, leading to theft of intellectual property, credential harvesting, and network reconnaissance. Victim sectors include aerospace defense and telecommunications, with potential financial losses from data exfiltration and operational disruption estimated in the tens of millions of dollars per incident based on similar RAT campaigns.
Organizations should enable AMSI and PowerShell script block logging, deploy EDR with behavioral detection rules for process hollowing (e.g., Sigma rule for T1055.012), and block known C2 IPs via firewall. Applying the Exchange patch for CVE‑2023‑21707 and enforcing application whitelisting for LNK file execution are critical first steps.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.