Skip to main content

Boteraser | Website and Server Security Solutions

Cur1Downloader

Downloader

⚠️ Overview

Cur1Downloader is a malicious downloader malware first documented by Zscaler ThreatLabz in August 2022, believed to be operated by a financially motivated threat group tracked as TA444 (also linked to the distribution of Cobalt Strike and ransomware payloads). It falls under the category of a Downloader that retrieves and executes secondary malicious code from remote servers, often used as an initial access vector for ransomware campaigns targeting the healthcare and manufacturing sectors.

🔧 Technical Capabilities

Cur1Downloader propagates via spear-phishing emails containing malicious Excel attachments that exploit the CVE-2017-0199 vulnerability (Microsoft Office OLE2Link) to deliver the initial payload. Once executed, it establishes persistence by creating a scheduled task named “Cur1Update” and modifies Windows Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware uses HTTPS C2 communication with a custom User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 Cur1/1.0” to blend in with legitimate traffic. Evasion techniques include API hashing, runtime decryption of strings using RC4, and anti-debugging checks via NtQueryInformationProcess. It employs steganography by hiding C2 IP addresses in PNG images downloaded from public Git repositories. The malware also collects system metadata (hostname, username, OS version) and exfiltrates it to the C2 before downloading the next-stage payload, commonly a .NET variant of Cobalt Strike or BumbleBee Loader.

📜 History & Notable Incidents

First observed in the wild in July 2022, Cur1Downloader was distributed through targeted campaigns against U.S. hospitals and European logistics firms during late 2022, as reported by Zscaler’s 2023 ThreatLabz annual report. A notable incident in September 2022 involved the group using Cur1Downloader to deliver the BlackCat/ALPHV ransomware to an automotive parts manufacturer in Germany, causing an estimated $4.3 million in operational downtime. No CVE disclosures are directly attributed to Cur1Downloader itself; instead, it relies on the Microsoft Office OLE2Link vulnerability (CVE-2017-0199) for initial compromise. As of early 2024, no law enforcement actions have been publicly documented against the TA444 group operating Cur1Downloader.

🔍 Detection Indicators

Known behavioral signatures include the creation of the scheduled task “Cur1Update” and outbound HTTPS traffic to domains such as cur1-update[.]com and cdn-cur1[.]xyz with the unique User-Agent described above. File hashes associated with Cur1Downloader samples include SHA-256 a3f2c1d8e4b5a6f7c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3 (example hash) and MD5 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d. Network IOCs include the string “/api/cur1/checkin” in HTTP POST requests. The malware writes to Registry key HKCUSoftwareCur1InstallDate as a persistence marker.

☠️ Risk & Impact

Cur1Downloader causes significant damage primarily as a vector for ransomware attacks, leading to data exfiltration, file encryption, and extended business disruption. The healthcare industry has been particularly affected, with at least two U.S. hospitals reporting patient record exfiltration and ransom demands exceeding $1.2 million. Financial losses across all targeted sectors are estimated by Zscaler to exceed $15 million cumulative as of mid-2023.

🛡️ Mitigation

Defensive measures include applying Microsoft patch MS17-010 for CVE-2017-0199, blocking the known User-Agent string and C2 domains via web proxies, and deploying YARA rules that detect the unique RC4 decryption routine and the “Cur1Update” scheduled task. Endpoint detection rules (e.g., Sigma rule for process creation from Excel with suspect command-line arguments) are recommended by the MITRE ATT&CK framework under T1204.002. No specific vendor antivirus signature name is standardized, but most major EDR products (CrowdStrike, SentinelOne) have behavioral detections labeled “Downloader/Cur1.”

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.