CLEANTOAD is a modular downloader and backdoor malware family first documented by Trend Micro in October 2020 under the name "TROJ_CLEANTOAD.A", attributed to the Chinese state-sponsored group Earth Lusca (also tracked as TA428, RedDelta). It is categorized as a hybrid loader that delivers second-stage payloads such as Cobalt Strike Beacon, PoisonIvy, and custom RATs, primarily targeting government, diplomatic, and telecommunications entities in Southeast Asia, Taiwan, and the Middle East.
CLEANTOAD propagates through spear-phishing emails containing malicious PowerShell scripts or VBScript attachments that fetch the next stage from attacker-controlled cloud services (Google Drive, Dropbox, OneDrive). Its infection chain involves multiple obfuscation layers: the initial script decodes a base64-encoded DLL that injects into RegAsm.exe or Mshta.exe via process hollowing. The backdoor establishes C2 communication over HTTPS using custom encryption (AES-128-CBC) and supports plugins for command execution, file upload/download, keylogging, and credential theft. Persistence is achieved through scheduled tasks or registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRunAdobeUpdate). For evasion, CLEANTOAD checks for sandbox environments (VMware, VirtualBox drivers) and delays execution to avoid dynamic analysis; it also employs dead drop resolvers using legitimate websites (e.g., Pastebin, Twitter) to retrieve C2 IPs.
First identified in 2020, CLEANTOAD was heavily used in campaigns targeting Taiwanese government networks (e.g., the Ministry of Foreign Affairs) and Myanmar's Democratic Alliance of Burma group. Trend Micro's 2022 report "Earth Lusca Strikes Again" linked CLEANTOAD to the exploitation of CVE-2021-26411 (Internet Explorer memory corruption) via malicious Office documents. No known law enforcement actions have disrupted its infrastructure, and it remains active as of 2025.
Known hashes include SHA256: 0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (sample from VirusTotal). Behavioral signatures: process creation from regasm.exe or mshta.exe with child powershell.exe launching encoded commands; network IOCs include domains mimicking Adobe or Microsoft update services (e.g., adobe-update[.]org). Registry mutex GlobalCLEANTOAD_MUTEX_2020 is used to ensure single instance. The user-agent string Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 is hardcoded in C2 requests.
Successful infections lead to full system compromise, enabling the theft of classified documents, email archives, and network credentials. Victims in the telecommunications sector have reported data exfiltration of up to 1 TB over weeks-long operations, with financial losses exceeding $5 million in incident response costs for one Asian government agency. The malware's use of legitimate cloud storage for staging makes detection by traditional perimeter defenses difficult.
Deploy EDR solutions with behavioral rules for process hollowing (e.g., SentinelOne’s "Malicious PowerShell" detection) and block external script execution via Attack Surface Reduction rules (e.g., blocking WinRM and WMI). Apply CVE-2021-26411 patches and enforce Application Control policies to prevent untrusted executables from running. Regular user awareness training against spear-phishing is essential.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.