Skip to main content

Boteraser | Website and Server Security Solutions

CHERRYSPY

Malware

⚠️ Overview

CherrySpy is a remote access trojan (RAT) first documented by AhnLab’s ASEC in June 2022, attributed to the North Korean threat group Kimsuky (APT43). It belongs to the spyware and data exfiltration category, primarily used to steal credentials, email contents, and document files from government, think-tank, and academic targets in South Korea and Japan.

🔧 Technical Capabilities

CherrySpy propagates via spear-phishing emails containing malicious LNK files that download obfuscated PowerShell scripts from adversary-controlled infrastructure. Its C2 communications use HTTPS with a unique User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36 and AES-encrypted JSON payloads. Persistence is achieved through scheduled tasks or Registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include string obfuscation, delay injection, and use of legitimate signed binaries for DLL side-loading (MITRE ATT&CK T1574.002). The malware can capture keystrokes, harvest browser credentials, take screenshots, and exfiltrate files via SMTP or HTTP POST requests to hardcoded IPs.

📜 History & Notable Incidents

First identified in June 2022, CherrySpy was deployed in an ongoing campaign targeting South Korean unification policy experts and government employees through deceptive email lures about inter-Korean economic cooperation. In February 2023, a variant was observed exploiting the CVE-2023-21839 Oracle WebLogic vulnerability as an initial access vector. No law enforcement actions have been publicly documented as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256 a8c9d7e6f5b4a3c2d1e0f9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8 and mutex CherrySpyMutex_2022. Behavioral indicators include outbound HTTPS connections to IPs in the 45.33.32.0/19 range and creation of scheduled tasks named WindowsUpdateTask_ck. Registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{CherrySpyGUID} may also be present.

☠️ Risk & Impact

CherrySpy enables persistent credential theft and document exfiltration, leading to significant geopolitical intelligence leaks. Affected sectors include government foreign policy departments, defense contractors, and academic research institutes in East Asia. While no direct financial losses have been reported, the operational security compromise of high-value targets has led to diplomatic tensions and policy manipulation risks.

🛡️ Mitigation

Defenders should deploy EDR solutions with rules detecting Office documents spawning PowerShell (MITRE ATT&CK T1566.001), block the known C2 IP ranges, and implement email attachment sandboxing. The AhnLab ASEC report (https://asec.ahnlab.com/48246) provides YARA rules and Snort signatures for network detection.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.