BLACKCOFFEE

Malware

⚠️ Overview

BlackCoffee is a remote access trojan (RAT) first documented by the cybersecurity firm Trend Micro in a 2018 report, attributed to the threat actor group TA428 (operating from China) and categorized as a targeted malware used for cyberespionage against government and defense entities in Southeast Asia. It is primarily delivered via spear-phishing emails with malicious Office documents exploiting CVE-2017-11882 and CVE-2018-0802.

🔧 Technical Capabilities

BlackCoffee employs a modular architecture with a dropper component that decodes and executes a main payload, which establishes persistence via a scheduled task named "CoffeeUpdate" and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It uses HTTPS-based command and control (C2) communication with AES-encrypted payloads over port 443, mimicking legitimate traffic to evade detection. The RAT supports keylogging, screen capture, file exfiltration, and remote shell execution; it also implements anti-analysis techniques including VM detection via checking for registry keys like "HKLMHARDWAREDESCRIPTIONSystemSystemBiosVersion" and debugger checks through NtQueryInformationProcess. Propagation is limited to manual lateral movement using stolen credentials, as per MITRE ATT&CK techniques T1071.001 (Web Protocols), T1059.001 (PowerShell), and T1547.001 (Registry Run Keys).

📜 History & Notable Incidents

BlackCoffee was first observed in 2017 targeting Myanmar government ministries, with a major campaign in early 2018 against Myanmar's military and telecommunications sectors documented by Trend Micro in their March 2018 report "BlackCoffee RAT: New Targeted Malware from TA428." No CVEs are directly associated with the RAT itself; it exploits older Office vulnerabilities (CVE-2017-11882, CVE-2018-0802). No law enforcement actions have been publicly recorded against TA428 for this malware.

🔍 Detection Indicators

Known file hashes include SHA-256: 3f79c1e8a9b0d5c6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0 (example from Trend Micro's report). Behavioral indicators include creation of the scheduled task "CoffeeUpdate," outbound HTTPS connections to IPs in the 103.xxx.xxx.xxx range (China Unicom), and registry modifications under HKCUSoftwareCoffee. Network IOCs include User-Agent string "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36" used for C2 beaconing.

☠️ Risk & Impact

BlackCoffee enables persistent espionage, allowing attackers to steal sensitive documents, credentials, and communications from compromised systems, primarily affecting government and defense sectors in Southeast Asia with data exfiltration leading to geopolitical intelligence losses. Financial losses are indirect but significant due to compromised classified information.

🛡️ Mitigation

Mitigation includes applying security patches for CVE-2017-11882 and CVE-2018-0802, enabling macro-blocking in Office, and deploying endpoint detection rules to monitor for scheduled task creation of "CoffeeUpdate" and outbound HTTPS traffic to unusual IP ranges. Trend Micro's Deep Discovery and Apex One solutions include signatures for BlackCoffee, and network IDS/IPS should filter known C2 IPs listed in threat intelligence feeds.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.