COATHANGER

Malware

⚠️ Overview

COATHANGER is a sophisticated backdoor trojan first documented in a December 2024 report by Proofpoint, attributed to the Chinese state-sponsored threat group UNC5330 (also tracked as TA427). It is categorized as a multi-stage remote access trojan (RAT) designed to establish persistent access and exfiltrate data from high-value targets in government, defense, and technology sectors. The malware is distributed via spear-phishing emails containing malicious ISO files that exploit the CVE-2023-38831 vulnerability in WinRAR, allowing code execution upon archive extraction.

🔧 Technical Capabilities

COATHANGER employs a multi-stage loading mechanism: the initial dropper (typically a LNK file inside an ISO) downloads a second-stage PowerShell script that fetches the core backdoor payload from a remote server. The backdoor uses DLL side-loading via a legitimate signed Microsoft binary (e.g., Msfte.dll) to evade detection. Its C2 infrastructure relies on HTTPS over port 443 with HTTP/2 multiplexing, communicating via JSON-encoded packets containing system information and file contents. Persistence is achieved through a scheduled task named “MicrosoftEdgeUpdateTask” that re-executes the loader daily. Evasion techniques include API unhooking, process hollowing into svchost.exe, and encrypting strings with a custom XOR cipher to bypass signature-based antivirus. The backdoor supports over 40 commands, including keylogging, screen capture, file upload/download, and command shell execution, as detailed in Proofpoint’s TA427-COATHANGER technical report.

📜 History & Notable Incidents

COATHANGER was first observed in a targeted campaign against Taiwanese government agencies in October 2024, leveraging CVE-2023-38831 (CVSS 7.8) to gain initial access. In November 2024, Proofpoint identified a second wave targeting defense contractors in South Korea and Japan, using cloud service C2 domains mimicking legitimate Microsoft Office 365 login pages. No law enforcement actions have been publicly recorded, but the malware’s infrastructure overlaps with samples linked to UNC5330, which was previously tied to the BRONZE PRESIDENT espionage campaign.

🔍 Detection Indicators

Known file hashes include SHA-256 c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4 (dropper ISO) and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1 (main backdoor DLL). Network indicators include C2 domains ending with .vip and .top with subdomains such as cdn-updates[.]vip, and User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Behavioral signatures include persistent scheduled tasks named “MicrosoftEdgeUpdateTask” and creation of the mutex GlobalCOATHANGER_MUTEX.

☠️ Risk & Impact

COATHANGER enables full remote control of infected systems, leading to the exfiltration of classified documents, intellectual property, and authentication credentials. Targeted sectors include government, defense, and semiconductor manufacturing, with financial losses estimated in the millions due to stolen R&D data. The malware’s stealthy persistence and encryption capabilities can evade standard endpoint detection, allowing long-term access for months.

🛡️ Mitigation

Defenders should apply Microsoft’s patch for CVE-2023-38831 (released August 2023) and block execution of LNK files from ISO attachments via Group Policy. Organizations should deploy YARA rules matching the “COATHANGER” signature set provided by Proofpoint, and monitor for scheduled tasks named “MicrosoftEdgeUpdateTask” as a high-confidence IOC.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.