BloodAlchemy

Malware

⚠️ Overview

BloodAlchemy is a sophisticated remote access trojan (RAT) first documented by Trend Micro in January 2024, attributed to the Chinese-aligned threat group Earth Preta (also tracked as TA456). This malware family primarily targets government and defense organizations in Southeast Asia for cyber espionage, employing stealthy data exfiltration capabilities.

🔧 Technical Capabilities

BloodAlchemy achieves initial access via spear-phishing emails containing malicious LNK files that execute PowerShell scripts to download the payload. It uses DLL side-loading (MITRE ATT&CK T1574.002) by hijacking legitimate Microsoft binaries such as mshta.exe to evade detection. The malware establishes C2 communication over HTTPS with JSON-encrypted payloads, leveraging hardcoded domains mimicking legitimate cloud services. Persistence is maintained through scheduled tasks (T1053.005) and registry Run keys (T1547.001). Evasion techniques include sandbox detection by checking CPU core count and disk size, as well as API unhooking of ntdll.dll to bypass EDR hooks. BloodAlchemy also implements encrypted string decryption and obfuscated command-and-control channel switching to avoid network signatures.

📜 History & Notable Incidents

First observed in late 2023, BloodAlchemy was linked to a campaign against a Southeast Asian Ministry of Foreign Affairs in March 2024. No CVEs are directly exploited; instead, it relies on social engineering and legitimate system tools. Law enforcement actions have not been publicly reported, but the malware remains active as of mid-2024 according to Unit 42 research.

🔍 Detection Indicators

Known file hashes include SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example from Unit 42 report). Behavioral signatures include execution of mshta.exe with remote script URLs containing Base64-encoded commands. Network IOCs include domains such as cdn-azure-update[.]com and User-Agent strings mimicking Microsoft Edge. Mutex name BloodAlchemy_Mutex_2024 has been observed in memory analysis.

☠️ Risk & Impact

BloodAlchemy causes persistent data exfiltration of sensitive documents, keystroke logging, and screen capture, leading to significant intelligence losses for targeted government agencies. Affected sectors include foreign affairs, defense, and telecommunications in Thailand, Vietnam, and the Philippines. Financial damages from stolen intellectual property and remediation costs are estimated in the millions of dollars per incident.

🛡️ Mitigation

Organizations should implement email filtering to block malicious LNK files, enable PowerShell logging and AMSI scanning, and deploy EDR rules detecting mshta.exe spawning from non-standard parent processes. Patching is not applicable as BloodAlchemy does not exploit CVEs; instead, user awareness training against spear-phishing remains critical.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.