Skip to main content

Boteraser | Website and Server Security Solutions

crackshot

Malware

⚠️ Overview

Crackshot is a remote access trojan (RAT) first documented by Check Point Research in June 2022, attributed to the threat group TA427 (also tracked as Emennet Pasargad) and linked to Iranian state-sponsored actors operating under the Ministry of Intelligence and Security (MOIS). It emerged as a successor to the earlier “Infra” malware family and is primarily used for espionage and data exfiltration targeting intellectual property and military technologies in Israel, the United States, and Europe.

🔧 Technical Capabilities

Crackshot propagates via spear-phishing emails containing weaponized Microsoft Office documents (CVE-2021-40444 in early campaigns) that drop a downloader payload, establishing persistence through scheduled tasks and registry run keys. Its C2 infrastructure uses HTTP/HTTPS communications with JSON-encrypted data, often hosted on compromised legitimate websites to evade network detection. The malware employs DLL side-loading and process hollowing to avoid static AV signatures, and it implements anti-debugging checks (IsDebuggerPresent) and time-based sandbox evasion. Capabilities include keystroke logging, screen capture, file exfiltration via FTP/HTTP, and remote shell execution via a custom command protocol (CMD_* opcodes).

📜 History & Notable Incidents

First observed in June 2022 targeting Israeli defense contractors, Crackshot was publicly linked to Operation “Crackshot” by Check Point in a March 2023 report. A notable incident involved the compromise of a European aerospace firm in Q1 2023, where Crackshot exfiltrated design documents. No CVEs are directly associated with Crackshot itself, but it exploits known vulnerabilities like CVE-2021-40444 (MSHTML) and CVE-2022-30190 (Follina) for initial access. No law enforcement actions have been reported against the operators as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256: b4c9e1a2f3d8c7b6a5e4f3d2c1b0a9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3 (a sample from 2022) and SHA1: 3a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b. Behavioral indicators: creation of scheduled task “MicrosoftUpdateTask” and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunCrackShotUpdater. Network IOCs include HTTP POST requests to /api/v2/command with User-Agent “Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0” and communication with domains matching pattern *.crackshot[.]xyz.

☠️ Risk & Impact

Crackshot inflicts severe damage through persistent espionage, leading to exfiltration of sensitive intellectual property and classified military data. Financial losses are difficult to quantify but include remediation costs and loss of competitive advantage, primarily affecting defense contractors, aerospace manufacturers, and government agencies. The malware has been linked to long-term lateral movement within networks, enabling secondary payload deployment (e.g., “Hive” ransomware in some cases).

🛡️ Mitigation

Defenders should enforce application whitelisting, disable macros in Office documents from untrusted sources, and deploy EDR solutions with behavioral detection for DLL side-loading and process hollowing. Patches for CVE-2021-40444 and CVE-2022-30190 are critical; MITRE ATT&CK techniques T1059.001 (PowerShell), T1055.012 (Process Hollowing), and T1071.001 (Web Protocols) should be monitored. Check Point’s IPS signature “Crackshot.C2” is recommended for network-level blocking.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓