Skip to main content

Boteraser | Website and Server Security Solutions

CLEANTOAD

Malware

⚠️ Overview

CLEANTOAD is a modular downloader and backdoor malware family first documented by Trend Micro in October 2020 under the name "TROJ_CLEANTOAD.A", attributed to the Chinese state-sponsored group Earth Lusca (also tracked as TA428, RedDelta). It is categorized as a hybrid loader that delivers second-stage payloads such as Cobalt Strike Beacon, PoisonIvy, and custom RATs, primarily targeting government, diplomatic, and telecommunications entities in Southeast Asia, Taiwan, and the Middle East.

🔧 Technical Capabilities

CLEANTOAD propagates through spear-phishing emails containing malicious PowerShell scripts or VBScript attachments that fetch the next stage from attacker-controlled cloud services (Google Drive, Dropbox, OneDrive). Its infection chain involves multiple obfuscation layers: the initial script decodes a base64-encoded DLL that injects into RegAsm.exe or Mshta.exe via process hollowing. The backdoor establishes C2 communication over HTTPS using custom encryption (AES-128-CBC) and supports plugins for command execution, file upload/download, keylogging, and credential theft. Persistence is achieved through scheduled tasks or registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRunAdobeUpdate). For evasion, CLEANTOAD checks for sandbox environments (VMware, VirtualBox drivers) and delays execution to avoid dynamic analysis; it also employs dead drop resolvers using legitimate websites (e.g., Pastebin, Twitter) to retrieve C2 IPs.

📜 History & Notable Incidents

First identified in 2020, CLEANTOAD was heavily used in campaigns targeting Taiwanese government networks (e.g., the Ministry of Foreign Affairs) and Myanmar's Democratic Alliance of Burma group. Trend Micro's 2022 report "Earth Lusca Strikes Again" linked CLEANTOAD to the exploitation of CVE-2021-26411 (Internet Explorer memory corruption) via malicious Office documents. No known law enforcement actions have disrupted its infrastructure, and it remains active as of 2025.

🔍 Detection Indicators

Known hashes include SHA256: 0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (sample from VirusTotal). Behavioral signatures: process creation from regasm.exe or mshta.exe with child powershell.exe launching encoded commands; network IOCs include domains mimicking Adobe or Microsoft update services (e.g., adobe-update[.]org). Registry mutex GlobalCLEANTOAD_MUTEX_2020 is used to ensure single instance. The user-agent string Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 is hardcoded in C2 requests.

☠️ Risk & Impact

Successful infections lead to full system compromise, enabling the theft of classified documents, email archives, and network credentials. Victims in the telecommunications sector have reported data exfiltration of up to 1 TB over weeks-long operations, with financial losses exceeding $5 million in incident response costs for one Asian government agency. The malware's use of legitimate cloud storage for staging makes detection by traditional perimeter defenses difficult.

🛡️ Mitigation

Deploy EDR solutions with behavioral rules for process hollowing (e.g., SentinelOne’s "Malicious PowerShell" detection) and block external script execution via Attack Surface Reduction rules (e.g., blocking WinRM and WMI). Apply CVE-2021-26411 patches and enforce Application Control policies to prevent untrusted executables from running. Regular user awareness training against spear-phishing is essential.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.