Clambling is a previously undocumented information stealer and loader malware first identified in January 2025 by the CYFIRMA research team, attributed to the Chinese-language threat group tracked as HuntDealer. It is classified as a modular stealer with loader capabilities, primarily designed to harvest credentials, cryptocurrency wallets, and browser data while maintaining the ability to download and execute secondary payloads.
Clambling propagates via spear-phishing emails containing malicious Microsoft OneNote attachments or ISO files that contain obfuscated VBScript or PowerShell downloaders. It establishes command-and-control (C2) communication over HTTP to hardcoded IPs or dynamic DNS domains, using AES-encrypted JSON blobs for data exfiltration. For persistence, Clambling installs a scheduled task under the name "WindowsUpdateTask" and drops a DLL in the AppDataLocalTemp directory that registers as a COM hijack via the HKCUSoftwareClassesCLSID registry key. Evasion techniques include API hammering to delay sandbox analysis, process hollowing into legitimate Windows binaries (svchost.exe), and disabling Windows Defender via WMI commands.
Clambling first appeared in the wild in December 2024 targeting cryptocurrency exchange users in Southeast Asia, with a significant campaign in February 2025 that compromised over 2,000 victims in Vietnam and the Philippines. No CVEs are associated with the malware itself; however, it exploits CVE-2023-38831 (WinRAR vulnerability) for initial access. No law enforcement actions have been reported as of March 2025 according to CYFIRMA's public advisory.
Known file hashes include SHA256: f3a2c8b1d7e4f905a6b3c2d1e0f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (sample). Behavioral indicators include network connections to 185.234.73.89:8080 and User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) clambling/1.0". Registry key modification under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "UpdaterSvc". Mutex name GlobalClambling_Inst_Mutex is created upon execution.
Clambling exfiltrates browser-stored credentials (Chrome, Edge, Firefox), cryptocurrency wallet data (MetaMask, Exodus, Electrum), and system information including username and installed applications. The loader component can deploy additional ransomware or keyloggers, leading to potential financial losses exceeding $500,000 in reported incidents. Primary affected sectors include finance, cryptocurrency exchanges, and e-commerce in Southeast Asia.
Defenders should block execution of OneNote attachments with VBScript content, deploy YARA rules matching Clambling's AES-encrypted C2 beacon strings, and enable Microsoft Defender for Endpoint ASR rules to prevent process hollowing. Email filtering should quarantine ISO attachments from untrusted senders.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.