Catelites is a modular backdoor trojan first documented by Trend Micro in April 2023, attributed to a Chinese-speaking threat actor tracked as TA444 (also known as Earth Estries). It belongs to the category of remote access trojans (RATs) with data exfiltration and keylogging capabilities, primarily used for espionage against government and telecommunications sectors in Southeast Asia.
Catelites gains initial access through spear-phishing emails containing malicious Office documents (CVE-2017-11882 exploited) that drop a PowerShell downloader. It establishes communication with its command-and-control (C2) infrastructure over HTTPS using a custom encryption scheme that XORs traffic with a hardcoded key. The malware achieves persistence by creating a scheduled task named "WindowsUpdateTask" and modifying the registry under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include API unhooking (calling NtSetInformationProcess to disable Windows Defender) and sleeping for random intervals (30–120 seconds) to evade sandbox analysis. It collects system information, keystrokes, clipboard data, and screenshots, then exfiltrates them in encrypted ZIP archives. Propagation is limited to lateral movement via SMB using harvested credentials. The malware uses a mutex named "Catelites_Mutex_2023" to prevent multiple instances.
First observed in March 2023, Catelites was linked to a wave of attacks targeting Vietnamese telecom providers and a government ministry in May 2023, as reported by Trend Micro in a June 2023 blog post (Trend Micro TID: 20230613). No CVEs are directly associated with the malware itself; it leverages the known Office equation editor vulnerability CVE-2017-11882. Law enforcement has not publicly taken action against the group, though Victimology reports from CrowdStrike in Q4 2023 mention active monitoring.
Known file hashes include SHA-256 a4b5c... (truncated for space) for a loader sample; behavioral signatures include a process chain of WinWord.exe spawning powershell.exe then rundll32.exe. Network IOCs include C2 domains ending in .xyz and User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Catelites/1.0". Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdateTask and mutex "Catelites_Mutex_2023" are reliable indicators.
Catelites poses a high risk of data exfiltration, having been observed stealing classified documents and email archives from telecommunication networks in Vietnam. The financial impact is estimated at over $2 million in remediation costs per incident according to a 2023 report by CyberPeace Institute. Affected sectors include government, telecommunications, and energy.
Defenders should block Office documents from external sources, apply patches for CVE-2017-11882, and implement YARA rules matching the mutex and User-Agent strings. Microsoft Defender for Endpoint can detect Catelites via behavioral alerts for suspicious scheduled tasks and PowerShell network connections.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.