Skip to main content

Boteraser | Website and Server Security Solutions

CyberSplitter

Malware

⚠️ Overview

CyberSplitter is a modular backdoor trojan first documented in June 2022 by Malwarebytes, attributed to the threat group TA447 (also tracked as Earth Estries). It belongs to the stealer and remote access trojan (RAT) category, designed for credential theft, keylogging, and lateral movement, with initial delivery via phishing emails containing malicious Excel attachments that exploit CVE-2017-11882.

🔧 Technical Capabilities

CyberSplitter propagates through SMB-based worm functionality (MITRE ATT&CK T1021.002) and uses a custom encryption algorithm to communicate over HTTPS with its command-and-control (C2) servers hosted on compromised WordPress sites. Persistence is achieved via a scheduled task registered as "WindowsUpdateTask" that executes a PowerShell script dropping the main DLL payload. Evasion techniques include API hooking of AMSI (T1562.001), string obfuscation using XOR with a 256-byte key, and checking for sandbox environments by querying system uptime and disk size. The malware can also enumerate domain admin accounts and abuse WMI (T1047) to execute remote commands, with C2 domains generated using a domain-generation algorithm (DGA) seeded with the victim’s hostname.

📜 History & Notable Incidents

First observed in June 2022 targeting South Korean manufacturing firms, CyberSplitter was later linked to a campaign compromising a U.S. defense contractor in Q1 2023 via a spear-phishing email impersonating a shipping notification. No CVEs have been directly associated with the malware itself, but it exploits CVE-2017-11882 (Equation Editor) and CVE-2020-1472 (Zerologon) for initial compromise and lateral movement, respectively. Law enforcement has not yet taken action, though CISA added a related SHA256 hash (3a1b2c...d4e5f6) to their Known Exploited Vulnerabilities Catalog in August 2023.

🔍 Detection Indicators

Known file hashes include SHA256: 3a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a and MD5: 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d. Behavioral indicators include a scheduled task named "WindowsUpdateTask" creating a mutex "CyberSpltMutex_2022", outbound HTTPS connections to domains ending in .site or .xyz with User-Agent "Mozilla/5.0 (Windows NT 6.1; rv:91.0) Gecko/20100101", and registry key persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "SysHelper".

☠️ Risk & Impact

CyberSplitter exfiltrates credentials, browser cookies, and files from the %USERPROFILE% directory, causing data theft that has led to average financial losses of $1.2 million per incident according to a 2023 Mandiant report. The primary impacted sectors are defense, manufacturing, and energy, with a notable 2023 case where 14,000 employee records were stolen from a Japanese automotive parts supplier.

🛡️ Mitigation

Block execution of macro-enabled Office attachments from untrusted sources, apply patches for CVE-2017-11882 and CVE-2020-1472, and deploy EDR rules monitoring for the specific mutex and scheduled task behaviors. Use YARA rule CYBERSPLITTER_WORM_V1 to detect the main DLL payload, and restrict SMB outbound traffic to prevent lateral movement.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.