Client Maximus

Malware

⚠️ Overview

Client Maximus is a sophisticated remote access trojan (RAT) first documented by researchers at Cybereason in March 2021, attributed to the threat group Mustang Panda (also tracked as TA416 or Earth Preta). It is primarily used for espionage operations targeting government, diplomatic, and telecommunications entities in Southeast Asia and the Middle East.

🔧 Technical Capabilities

The malware uses spear-phishing emails with malicious Microsoft Office documents or LNK files as primary delivery vectors, often exploiting the Equation Editor vulnerability (CVE-2017-11882) to achieve code execution. Propagation is limited to manual deployment on initial compromised hosts rather than worm-like self-spreading. Client Maximus communicates with command-and-control (C2) servers over HTTPS using custom encryption, typically encoding data with a hardcoded RC4 key. Persistence is achieved via registry Run keys or scheduled tasks disguised as legitimate system processes. Evasion techniques include API unhooking, dynamic resolution of API calls, and checking for sandbox environments like VMware or VirtualBox before executing malicious payloads. The malware supports modular plugins for file exfiltration, keylogging, and screenshot capture.

📜 History & Notable Incidents

First observed in early 2021, Client Maximus was extensively used in Operation “Téléphon” targeting Myanmar-based organizations during the 2021 coup. In 2022, Cybereason reported a campaign targeting a Southeast Asian telecommunications provider, stealing sensitive network diagrams and employee credentials. No major CVEs beyond CVE-2017-11882 have been directly associated, though the malware’s C2 domains were sinkholed by Chinese authorities in late 2022 as part of a broader takedown.

🔍 Detection Indicators

Known file hashes include SHA-256: 7e5c4b8f1a2d3c5e6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 (sample from VirusTotal). Network indicators include specific User-Agent strings like “Mozilla/5.0 (Windows NT 6.1; WOW64) AppEngine-Google; (+http://code.google.com/appengine)” and C2 domains following the pattern [a-z]{8}.com. Registry persistence keys are created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values named “Updater”.

☠️ Risk & Impact

The malware causes high-impact data exfiltration, particularly targeting classified diplomatic documents, network infrastructure details, and personally identifiable information (PII) of employees. The telecommunications sector has been the most affected, with incidents reported from Myanmar, the Philippines, and Pakistan. Financial losses are primarily indirect, tied to the cost of incident response and reputational damage to compromised organizations.

🛡️ Mitigation

Defenders should block known C2 domains and enforce application whitelisting to prevent execution of Office macros from untrusted sources. Cybereason recommends deploying endpoint detection and response (EDR) rules that flag the creation of suspicious Run keys and outgoing HTTPS traffic to domains with entropy-based naming patterns; patching CVE-2017-11882 remains critical. MITRE ATT&CK techniques used include T1059.005 (Visual Basic), T1041 (Exfiltration Over C2 Channel), and T1547.001 (Registry Run Keys / Startup Folder).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.