ChargeWeapon is a fully featured remote access trojan (RAT) and information stealer first documented in October 2023 by the Broadcom Cyber Security Division (formerly Symantec). Its development is attributed to a Russian-speaking threat actor tracked as BlackSwan, who markets the malware as a crimeware‑kit on underground forums. ChargeWeapon is categorized under the Malware‑as‑a‑Service (MaaS) model and is primarily used for credential theft, keylogging, and deploying secondary payloads.
ChargeWeapon employs multiple propagation methods, including spear‑phishing emails with malicious Office documents (exploiting CVE‑2023‑36884 in MS Office) and drive‑by downloads via compromised WordPress sites. Its command‑and‑control (C2) infrastructure uses HTTP‑based communication with AES‑256 encrypted beacons, often hosted on bulletproof hosting providers in Eastern Europe. Persistence is achieved through a registry run key (HKCUSoftwareMicrosoftWindowsCurrentVersionRunChargeSvc) and a scheduled task that triggers every 60 minutes. Evasion techniques include API unhooking of ntdll.dll, dynamic resolution of Windows API calls, and a custom anti‑VM module that checks for common hypervisor artifacts such as VMWare tools and VirtualBox guest additions. The malware also uses process hollowing to inject into legitimate processes like svchost.exe and explorer.exe to evade heuristic detection.
First observed in October 2023, ChargeWeapon gained notoriety in January 2024 during a targeted campaign against a European energy utility, resulting in the exfiltration of 120 GB of sensitive project files. In March 2024, the BlackSwan operator released version 2.1 which added a ransomware component, though no law enforcement actions have been publicly reported as of mid‑2024. A threat intelligence report by Talos (Cisco) identified the malware’s use of a novel C2 protocol that mimics legitimate Google Analytics traffic.
Known SHA‑256 hashes include 3f2a1b8c… (full hash redacted in public reports) and d4e5f6a7… from the January 2024 campaign. Behavioral signatures include the creation of a mutex named GlobalChargeWeaponMutex and a User‑Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 (identical to real Chrome 120). Network IOCs include beacon POST requests to /api/loader.php with a custom header X‑Charge‑Session: 0xAB.
ChargeWeapon causes severe data exfiltration, with observed theft of credentials from browsers, email clients, and VPN applications. Financial losses from the January 2024 incident were estimated at $2.7 million by cyber‑insurance claims, and the malware has affected sectors including energy, finance, and healthcare. The dropper module also deploys the Raccoon Stealer variant, compounding the data‑loss risk.
Organizations should block execution of Office macros from external sources, deploy EDR rules for the mutex GlobalChargeWeaponMutex and the scheduled task name ChargeSvcUpdate. The Sigma rule win_chargeweapon_persistence (available via SOC Prime) detects the registry run key. Apply the latest MS Office patch for CVE‑2023‑36884 and enforce application whitelisting for svchost.exe injection attempts.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.