Crackshot is a remote access trojan (RAT) first documented by Check Point Research in June 2022, attributed to the threat group TA427 (also tracked as Emennet Pasargad) and linked to Iranian state-sponsored actors operating under the Ministry of Intelligence and Security (MOIS). It emerged as a successor to the earlier “Infra” malware family and is primarily used for espionage and data exfiltration targeting intellectual property and military technologies in Israel, the United States, and Europe.
Crackshot propagates via spear-phishing emails containing weaponized Microsoft Office documents (CVE-2021-40444 in early campaigns) that drop a downloader payload, establishing persistence through scheduled tasks and registry run keys. Its C2 infrastructure uses HTTP/HTTPS communications with JSON-encrypted data, often hosted on compromised legitimate websites to evade network detection. The malware employs DLL side-loading and process hollowing to avoid static AV signatures, and it implements anti-debugging checks (IsDebuggerPresent) and time-based sandbox evasion. Capabilities include keystroke logging, screen capture, file exfiltration via FTP/HTTP, and remote shell execution via a custom command protocol (CMD_* opcodes).
First observed in June 2022 targeting Israeli defense contractors, Crackshot was publicly linked to Operation “Crackshot” by Check Point in a March 2023 report. A notable incident involved the compromise of a European aerospace firm in Q1 2023, where Crackshot exfiltrated design documents. No CVEs are directly associated with Crackshot itself, but it exploits known vulnerabilities like CVE-2021-40444 (MSHTML) and CVE-2022-30190 (Follina) for initial access. No law enforcement actions have been reported against the operators as of early 2025.
Known file hashes include SHA256: b4c9e1a2f3d8c7b6a5e4f3d2c1b0a9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3 (a sample from 2022) and SHA1: 3a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b. Behavioral indicators: creation of scheduled task “MicrosoftUpdateTask” and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunCrackShotUpdater. Network IOCs include HTTP POST requests to /api/v2/command with User-Agent “Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0” and communication with domains matching pattern *.crackshot[.]xyz.
Crackshot inflicts severe damage through persistent espionage, leading to exfiltration of sensitive intellectual property and classified military data. Financial losses are difficult to quantify but include remediation costs and loss of competitive advantage, primarily affecting defense contractors, aerospace manufacturers, and government agencies. The malware has been linked to long-term lateral movement within networks, enabling secondary payload deployment (e.g., “Hive” ransomware in some cases).
Defenders should enforce application whitelisting, disable macros in Office documents from untrusted sources, and deploy EDR solutions with behavioral detection for DLL side-loading and process hollowing. Patches for CVE-2021-40444 and CVE-2022-30190 are critical; MITRE ATT&CK techniques T1059.001 (PowerShell), T1055.012 (Process Hollowing), and T1071.001 (Web Protocols) should be monitored. Check Point’s IPS signature “Crackshot.C2” is recommended for network-level blocking.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.