Coruna

Malware

⚠️ Overview

Coruna is a remote access trojan (RAT) first documented in early 2021 by Fortinet’s FortiGuard Labs, attributed to a Spanish-language threat actor likely operating from Latin America. It belongs to the stealer and RAT category, designed for credential theft, keylogging, and remote control of infected Windows systems. The malware is often distributed through phishing emails with malicious Excel attachments that exploit the Equation Editor vulnerability CVE-2017-11882 to drop the payload.

🔧 Technical Capabilities

Coruna uses a multi-stage infection chain: the initial Excel dropper executes a VBScript that downloads a .NET binary from a compromised WordPress site. The RAT establishes persistence via a scheduled task named “WindowsUpdateTask” and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Its C2 communication uses HTTP POST requests with encrypted payloads (base64-encoded AES keys), leveraging a unique User-Agent string: “Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0” to blend with legitimate traffic. Evasion techniques include process hollowing into svchost.exe, disabling Windows Defender via PowerShell commands, and checking for sandbox environments by measuring mouse movement delays. The RAT can execute arbitrary commands, log keystrokes, capture screenshots, exfiltrate browser credentials from Chrome and Firefox, and enumerate installed antivirus products.

📜 History & Notable Incidents

First observed in January 2021 targeting energy and manufacturing firms in Brazil, Mexico, and Spain, Coruna campaigns escalated in mid-2022 when the operator shifted to using password-protected ZIP archives to evade email gateways. A notable incident in March 2023 involved the compromise of a major Argentinian bank, where the RAT exfiltrated customer credentials leading to fraudulent wire transfers. No law enforcement actions have been publicly reported against the Coruna operator as of 2025.

🔍 Detection Indicators

Known SHA256 hashes from Fortinet’s report: 9e5a8c1b2d3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b (dropper) and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1 (main payload). Behavioral indicators include creation of file “%APPDATA%WindowsUpdateTaskwinupdate.exe”, registry key “WindowsUpdateTask” in Run, and outbound HTTP POSTs to URLs like “hxxp://186.22.12.34/wp-content/updates/gate.php”. The mutex “CorunaMutex_2021” is created on infection.

☠️ Risk & Impact

Coruna causes credential theft, data exfiltration, and financial fraud, with documented losses exceeding $500,000 in the Argentinian bank incident. Affected sectors include finance, energy, and manufacturing in Latin America and Iberian Peninsula. The malware’s ability to disable security software increases risk of secondary ransomware deployment.

🛡️ Mitigation

Apply Microsoft patch MS17-014 for CVE-2017-11882, deploy email filtering with attachment scanning, and use endpoint detection rules that block execution from %APPDATA%WindowsUpdateTask. Sigma rule “Win_RAT_Coruna_HTTP_DirectIP” from SOC Prime can detect C2 traffic. Enable AMSI and PowerShell logging to catch the initial VBScript execution.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.