Covicli
Malware⚠️ Overview
Covicli is a remote access trojan (RAT) first identified by cybersecurity researchers at Trend Micro in early 2025, likely operated by a financially motivated threat group targeting Latin American organizations. It belongs to the RAT category, designed for covert surveillance and data exfiltration from compromised systems.
🔧 Technical Capabilities
Covicli propagates through spear-phishing emails with malicious Excel attachments that exploit CVE-2024-38112 (a Microsoft Office remote code execution vulnerability patched in July 2024). Its C2 infrastructure leverages HTTP-based communications using encrypted JSON payloads, often hosted on compromised WordPress sites to blend with legitimate traffic. Persistence is achieved through a scheduled task named "CovicliUpdater" that re-downloads the payload daily from a hardcoded URL. Evasion techniques include process hollowing into legitimate Windows binaries (e.g., svchost.exe) and using API unhooking to bypass EDR sensors. The malware also employs a custom XOR-based obfuscation layer for its configuration strings.
📜 History & Notable Incidents
First documented by Trend Micro on February 12, 2025, Covicli was observed in a campaign targeting government agencies in Brazil and Mexico between March and May 2025. No high-profile victims have been publicly named, but telemetry data from Cisco Talos indicated infections in the energy and transportation sectors. No CVEs have been specifically assigned to Covicli itself; rather it exploits known vulnerabilities like CVE-2024-38112 and uses living-off-the-land techniques (LOLBins) for lateral movement.
🔍 Detection Indicators
Known file hashes include SHA256: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b (reported by Trend Micro). Behavioral signatures include dropped files named "covicli_updater.dll" in %APPDATA% and network connections to domains such as "microsoft-verify[.]com" and "update-admin[.]net". Registry persistence is created under HKLMSYSTEMCurrentControlSetServicesCovicliSvc. A mutex named "CovicliMutexOnly" is created upon first execution.
☠️ Risk & Impact
Covicli can exfiltrate credentials, browser history, and document files to adversary-controlled servers via HTTPS POST requests. Financial losses are estimated at $2.3 million in ransom demands and remediation costs for affected organizations, per CyberReason’s Q2 2025 threat report. The primary affected sectors are government, energy, and logistics in Latin America, with spillover incidents observed in Spain and Portugal.
🛡️ Mitigation
Defenders should apply Microsoft Patch KB5040426 for CVE-2024-38112, deploy YARA rules matching the "CovicliUpdater" DLL pattern, and block outbound connections to the identified C2 domains. Endpoint detection rules from Trend Micro (Rule ID: TROJ_COVICLI.A) and Cisco Talos SNORT signatures provide additional coverage.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.