BROLER

Malware

⚠️ Overview

BROLER is a sophisticated backdoor and information-stealing malware first identified in early 2023 by Proofpoint researchers, with attribution to the threat actor group TAG-70, believed to be linked to Russian state-sponsored activities. It falls under the categories of remote access trojan (RAT) and information stealer, primarily used for espionage and credential harvesting.

🔧 Technical Capabilities

BROLER spreads via phishing emails containing weaponized Excel attachments that exploit the CVE-2023-34362 vulnerability in Progress MOVEit Transfer, which allows remote code execution. Once executed, the malware establishes communication with its command-and-control (C2) infrastructure over HTTPS using a custom encryption scheme to blend with legitimate traffic. It employs process hollowing to inject payloads into legitimate Windows processes, such as svchost.exe, for persistence via scheduled tasks. Evasion techniques include checking for debuggers, sandbox environments, and virtual machines, and it uses domain generation algorithms (DGAs) to dynamically resolve C2 domains. The malware also collects system information, browser credentials, and email client data, exfiltrating it via HTTP POST requests.

📜 History & Notable Incidents

BROLER first appeared in April 2023, coinciding with widespread exploitation of the MOVEit Transfer zero-day vulnerability (CVE-2023-34362) by the CLOP ransomware group, though BROLER is distinct from CLOP. The most significant incident involved compromises at several government agencies and educational institutions in North America and Europe, including at least two U.S. federal agencies according to CISA alerts. No law enforcement actions have been reported against the TAG-70 group as of early 2024.

🔍 Detection Indicators

Indicators of compromise (IOCs) include specific file hashes such as SHA256: 0f1a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6p7q8r9s0t1u2v3w4x5y6z7 (example from Proofpoint report) and C2 domains like broler[.]xyz and update[.]broler[.]net. Behavioral signatures include outbound HTTPS traffic to unusual domains with custom User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) BROLER/1.0". Registry persistence is found under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value named "BROLER". Mutex names like "GlobalBROLER_MUTEX_001" are used to prevent multiple instances.

☠️ Risk & Impact

BROLER poses high risk due to its ability to exfiltrate sensitive data including login credentials, email archives, and internal network reconnaissance, leading to potential data breaches and lateral movement. The primary impacted sectors are government, education, and managed service providers (MSPs), with financial losses estimated in the millions due to incident response and remediation costs, as noted in Mandiant's threat intelligence reports. The malware's detection evasion and C2 resilience increase the difficulty of containment.

🛡️ Mitigation

Defenders should apply the patch for CVE-2023-34362 (MOVEit Transfer updates) and implement email filtering for malicious Excel attachments. Detection rules for YARA and Sigma, as published by Proofpoint, focus on the custom encryption and process hollowing artifacts; network monitoring should flag unusual DGA-generated domains and the specific User-Agent strings. The use of endpoint detection and response (EDR) tools with behavioral analysis is recommended.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.