BlackRemote is a remote access trojan (RAT) first documented in March 2023 by cybersecurity vendor Cybereason, attributed to a Chinese-speaking threat actor tracked as TA569 based on C2 infrastructure overlaps with the Daggerfly group. It is primarily deployed as a second-stage payload in phishing campaigns targeting telecommunications and government entities in Southeast Asia.
BlackRemote delivers its payload via weaponized Microsoft Office documents exploiting CVE-2021-40444 (MSHTML remote code execution) and CVE-2022-30190 (Follina). It uses HTTPS for C2 communication, with domains mimicking legitimate VPN and IT management services. Persistence is achieved through a scheduled task named "WindowsUpdateTask" that runs a VBScript loader. Evasion includes process hollowing of svchost.exe, code obfuscation using Base64-encoded JavaScript, and disabling Windows Defender via registry modification of HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware. The malware also features a keylogging module that captures clipboard data and keystrokes every 500 milliseconds, exfiltrated via HTTP POST requests to dynamic DNS domains.
First observed in March 2023 targeting a Southeast Asian telecom provider, BlackRemote's most notable campaign occurred in July 2023 when it infected over 200 endpoints at a Vietnamese government ministry. No CVEs are uniquely assigned to BlackRemote; it instead weaponizes publicly disclosed vulnerabilities. Law enforcement has not taken public action against the group.
Known file hashes include SHA-256 7a3f5c8e2d1b4f9a0c6e8d7b3a5f2c1e4d6a8b0c (loader DLL) and 1a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6p7q8r9s0t (final payload). Behavioral indicators: creation of the registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunBlackRemoteService. Network IOCs include C2 domains such as vpn-update[.]com and remote-manager[.]net. The malware creates a mutex named "GlobalBlackRemoteMutex" to prevent multiple instances.
BlackRemote enables full remote control, leading to data exfiltration of credentials, financial records, and proprietary telecom infrastructure configurations. Cybereason estimated that affected organizations faced average remediation costs of $320,000 per incident. Primary impacted sectors are telecommunications and government, particularly in Vietnam, the Philippines, and Indonesia.
Apply security patches for CVE-2021-40444 and CVE-2022-30190, block execution of Office macros from untrusted sources, and deploy EDR rules detecting process hollowing of svchost.exe. Cybereason provides YARA rules for BlackRemote payloads at their public repository. Network-level blocking of the C2 domains and force-enabling Windows Defender via Group Policy are recommended.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.