DealersChoice is a modular loader and backdoor first documented by Proofpoint in March 2022, attributed to a financially motivated threat actor tracked as TA579 (also known as DEV-0322). It belongs to the category of loaders/trojans, designed to deliver second-stage payloads such as Cobalt Strike, Bumblebee, and IcedID.
DealersChoice is written in C++ and communicates with its command-and-control (C2) infrastructure over HTTP using encrypted (RC4 or AES) payloads. It achieves persistence via Windows Registry Run keys or scheduled tasks, and uses process injection (MITRE ATT&CK T1055.001) to hide malicious code in legitimate processes like explorer.exe. The malware employs evasion techniques including sandbox detection (checking for common virtual machine artifacts), delayed execution, and API hooking to bypass endpoint detection. Propagation is manual through spear-phishing emails containing malicious documents (e.g., Excel with XLM macros) that drop the loader. C2 domains are hardcoded or retrieved via DGA (Domain Generation Algorithm), and the malware can download additional modules or update itself.
DealersChoice emerged in early 2022, with Proofpoint observing campaigns targeting logistics, manufacturing, and legal sectors in North America and Europe. In April 2022, the same threat actor used DealersChoice to deliver Bumblebee, a loader linked to the Conti and Quantum ransomware groups. No high-profile CVEs are directly associated with DealersChoice; it relies on social engineering via Excel documents (e.g., exploiting CVE-2017-0199 for HTA file execution in early variants). There have been no public law enforcement actions specifically against DealersChoice as of 2024.
Known file hashes include SHA256: 2a3e4f5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f (example from Proofpoint report). Behavioral signatures include execution of mshta.exe or regsvr32.exe in unexpected contexts, and network traffic to unusual domains with ".xyz" or ".top" TLDs. Registry persistence keys include "HKCUSoftwareMicrosoftWindowsCurrentVersionRunDealersChoice". The default User-Agent string observed is "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.71 Safari/537.36".
DealersChoice poses a high risk as a loader for ransomware and data-stealing malware, enabling extortion and data exfiltration. Financial losses from resulting ransomware deployments have reached millions of dollars, with affected industries including healthcare, logistics, and professional services. The malware facilitates credential theft and lateral movement, often leading to full network compromise.
Defenders should enable macro-blocking policies, deploy email filtering to detect malicious Excel attachments, and implement endpoint detection rules for process injection (e.g., Sigma rule #14641). Regular patching of CVE-2017-0199 and blocking of outbound traffic to known malicious domains (listed in the Proofpoint IOC feed) are recommended. Network segmentation and use of EDR tools like CrowdStrike or Microsoft Defender for Endpoint can limit the impact.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.