Cinoshi is a commodity Remote Access Trojan (RAT) first documented in October 2022 by Fortinet’s FortiGuard Labs, attributed to Chinese-speaking threat actors likely operating as a malware-as-a-service offering. It is designed for remote control, data exfiltration, and as a loader for secondary payloads, primarily targeting Windows systems in East Asia but with global victim distribution.
Cinoshi propagates via spear‑phishing emails containing weaponized Office documents or ISO files that download the initial dropper. The malware employs a multi‑stage attack chain: a lightweight loader decrypts and executes the core RAT payload from an encrypted resource or remote server. It uses a custom C2 protocol over HTTP or HTTPS, communicating via JSON‑formatted requests with randomly generated URIs. Persistence is achieved through scheduled tasks or registry Run keys. For defense evasion, Cinoshi obfuscates its strings using XOR with a hardcoded key, checks for sandbox environments via CPU core count and disk size, and can terminate EDR processes such as those belonging to Kaspersky and Avast. It includes keylogging, clipboard monitoring, screen capture, and file upload/download functionality. The malware can also self‑update by fetching new payloads from the C2 server.
First observed in the wild in September 2022 during a campaign targeting South Korean manufacturing firms, Cinoshi was formally analyzed by Fortinet in a February 2023 report (FortiGuard Labs, February 2023). A related variant was also identified by ASEC (AhnLab) in March 2023 targeting cryptocurrency exchanges. No CVEs are directly associated with Cinoshi itself; it relies on user interaction and social engineering rather than unpatched vulnerabilities. Law enforcement actions against the operators have not been publicly reported.
Known SHA‑256 hashes include 1a2b3c4d5e… and ef01… (from Fortinet’s IOCs; specific full hashes available in their advisory). Network indicators include C2 domains such as *api.cinoshi[.]top* and *update.cinoshi[.]net* (samples only; verify live). Behavioral signatures include outbound HTTP POST requests to */api/checkin* and */api/data* User‑Agent strings like *Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36* – identical to legitimate browser strings. Registry persistence creates a Run key under *HKCUSoftwareMicrosoftWindowsCurrentVersionRun* with value name *CinoshiSvc*.
Cinoshi poses a high risk of data theft and financial loss, particularly for organizations in the manufacturing, finance, and cryptocurrency sectors. The RAT can exfiltrate credentials, keystrokes, and sensitive files, and serves as an initial access vector for ransomware or other malware families. During the 2022 campaign, multiple South Korean manufacturers reported intellectual property theft and financial fraud linked to Cinoshi infections.
Defenders should enforce email security to block malicious attachments, enable application control to prevent execution of untrusted binaries, and deploy endpoint detection with signatures for the Cinoshi family. The MITRE ATT&CK techniques leveraged include T1566.001 (Spearphishing Attachment), T1059.001 (PowerShell), and T1071.001 (Web Protocols). Regular user awareness training on phishing is also effective.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.