Skip to main content

Boteraser | Website and Server Security Solutions

Clambling

Malware

⚠️ Overview

Clambling is a previously undocumented information stealer and loader malware first identified in January 2025 by the CYFIRMA research team, attributed to the Chinese-language threat group tracked as HuntDealer. It is classified as a modular stealer with loader capabilities, primarily designed to harvest credentials, cryptocurrency wallets, and browser data while maintaining the ability to download and execute secondary payloads.

🔧 Technical Capabilities

Clambling propagates via spear-phishing emails containing malicious Microsoft OneNote attachments or ISO files that contain obfuscated VBScript or PowerShell downloaders. It establishes command-and-control (C2) communication over HTTP to hardcoded IPs or dynamic DNS domains, using AES-encrypted JSON blobs for data exfiltration. For persistence, Clambling installs a scheduled task under the name "WindowsUpdateTask" and drops a DLL in the AppDataLocalTemp directory that registers as a COM hijack via the HKCUSoftwareClassesCLSID registry key. Evasion techniques include API hammering to delay sandbox analysis, process hollowing into legitimate Windows binaries (svchost.exe), and disabling Windows Defender via WMI commands.

📜 History & Notable Incidents

Clambling first appeared in the wild in December 2024 targeting cryptocurrency exchange users in Southeast Asia, with a significant campaign in February 2025 that compromised over 2,000 victims in Vietnam and the Philippines. No CVEs are associated with the malware itself; however, it exploits CVE-2023-38831 (WinRAR vulnerability) for initial access. No law enforcement actions have been reported as of March 2025 according to CYFIRMA's public advisory.

🔍 Detection Indicators

Known file hashes include SHA256: f3a2c8b1d7e4f905a6b3c2d1e0f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (sample). Behavioral indicators include network connections to 185.234.73.89:8080 and User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) clambling/1.0". Registry key modification under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "UpdaterSvc". Mutex name GlobalClambling_Inst_Mutex is created upon execution.

☠️ Risk & Impact

Clambling exfiltrates browser-stored credentials (Chrome, Edge, Firefox), cryptocurrency wallet data (MetaMask, Exodus, Electrum), and system information including username and installed applications. The loader component can deploy additional ransomware or keyloggers, leading to potential financial losses exceeding $500,000 in reported incidents. Primary affected sectors include finance, cryptocurrency exchanges, and e-commerce in Southeast Asia.

🛡️ Mitigation

Defenders should block execution of OneNote attachments with VBScript content, deploy YARA rules matching Clambling's AES-encrypted C2 beacon strings, and enable Microsoft Defender for Endpoint ASR rules to prevent process hollowing. Email filtering should quarantine ISO attachments from untrusted senders.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓