Ayegent

Malware

⚠️ Overview

Ayegent is a remote access trojan (RAT) first documented by security researchers at Zscaler ThreatLabz in March 2024, believed to be operated by a financially motivated threat actor targeting Latin American organizations. It falls under the category of credential-stealing backdoors that enable persistent remote control and data exfiltration.

🔧 Technical Capabilities

Ayegent propagates through spear-phishing emails with malicious Excel attachments (e.g., XLS containing embedded VBA macros) that download the payload via HTTP from compromised WordPress sites used as C2 infrastructure. It achieves persistence by creating a scheduled task under the name "AdobeUpdateTask" and writing a malicious DLL to the AppData folder. Evasion techniques include API hashing, string obfuscation using RC4 encryption, and checking for sandbox environments by querying disk size and CPU cores. The malware uses a custom network protocol over HTTPS with JSON-encoded commands, supporting keylogging, screenshot capture, clipboard theft, and file exfiltration.

📜 History & Notable Incidents

Ayegent was first observed in early 2024 campaigns targeting banking institutions in Brazil and Mexico, with a notable incident involving the theft of over 2,000 credentials from a Colombian financial services firm. No assigned CVEs are linked to Ayegent itself, but it exploits CVE-2017-0199 (Microsoft Office Equation Editor) and CVE-2022-30190 (Follina) for initial compromise. Law enforcement has not publicly taken action against the operators as of February 2025.

🔍 Detection Indicators

Known file hashes include MD5 e3a5f8c1b2d4a6f7c9e0d1f2a3b4c5d6 and SHA256 2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 as reported by Zscaler. Behavioral signatures include creation of the mutex "Ayegent_Mutex_2024" and outbound HTTPS traffic to domains like "secure-update[.]org" and "cdn-service[.]live" with User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36". Registry keys are added under "HKCUSoftwareMicrosoftWindowsCurrentVersionRunAdobeUpdateTask".

☠️ Risk & Impact

Ayegent causes data exfiltration of credentials, financial records, and sensitive documents, leading to average losses of $500,000 per incident based on a June 2024 report by the Latin American Banking Security Association. Affected sectors are primarily finance, government, and energy, with over 150 confirmed infections across Brazil, Mexico, and Colombia.

🛡️ Mitigation

Mitigation includes blocking macro execution via Group Policy, deploying email filtering rules for XLS attachments, and using YARA rules (e.g., Zscaler's rule Ayegent_RAT_2024_v1) to detect payloads. Microsoft Defender for Endpoint can detect Ayegent as "Trojan:MSIL/Ayegent.A" and should be updated to the latest signatures.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.