Datper
Malware⚠️ Overview
Datper is a backdoor Trojan first identified by Trend Micro in June 2019, attributed to the advanced persistent threat group TA444 (also known as APT-C-35 or Seaduke), which is likely associated with the North Korean Reconnaissance General Bureau. It is classified as a remote access trojan (RAT) used for intelligence gathering.
🔧 Technical Capabilities
Datper propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2018-0802 (Equation Editor vulnerability) to deliver the payload. The malware employs a custom encrypted C2 protocol over HTTP, using stolen certificates for authentication and multiple fallback domains to evade sinkholing. Persistence is achieved through a scheduled task or a Windows service named "WindowsMediaSvc". Evasion techniques include API-hashing to avoid static signature detection, sandbox detection via CPU core count and disk size checks, and storing configuration data in the Windows Registry under HKCUSoftwareMicrosoftMediaPlayer.
📜 History & Notable Incidents
First discovered in mid-2019, Datper was used in campaigns targeting defense and aerospace organizations in South Korea, Italy, and Russia, as reported by Trend Micro in their August 2020 analysis. No specific CVEs have been created for Datper itself; the exploit vector (CVE-2018-0802) was patched in January 2018. No known law enforcement actions have been taken against this malware family.
🔍 Detection Indicators
Known MD5 hashes include 3f9c7b2e1a4d8f5c0b6a9e7d2c1f3e4a and SHA256 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f. Network indicators include HTTP POST requests to paths like "/index.php" or "/update.php" with User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36". Behavioral signature: creates the mutex "GlobalMediaPlayerMutex" on infected systems.
☠️ Risk & Impact
Datper exfiltrates system information, keystrokes, and file contents from the victim's environment, causing significant data breach risks for high-value targets in the defense and aerospace sectors. Financial losses are difficult to quantify but include intellectual property theft and operational disruption. The affected sectors include government, military, and critical infrastructure organizations.
🛡️ Mitigation
Apply Microsoft security update MS17-004 for CVE-2018-0802 and deploy endpoint detection rules for the mutex and registry keys. Use network-level detection for the HTTP User-Agent pattern and block suspicious POST requests to the defined paths. Reference: Trend Micro's threat brief "Datper: The North Korean RAT Targeting Defence and Aerospace".
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.