Skip to main content

Boteraser | Website and Server Security Solutions

DealPly

Malware

⚠️ Overview

DealPly is a modular malware loader first documented by Palo Alto Networks Unit 42 in May 2022, associated with a financially motivated threat cluster tracked as TA577 (also known as UNC1878), primarily delivering Cobalt Strike and later ransomware payloads such as BlackByte and BlackCat. It functions as a downloader and backdoor, categorized under trojan and loader malware, with initial access often achieved through phishing campaigns exploiting CVE-2021-40444 (MSHTML remote code execution).

🔧 Technical Capabilities

DealPly propagates via spear-phishing emails containing rogue Microsoft Office documents or ISO files that, when opened, execute a VBA script or shortcut (LNK) to download the loader. Its attack vector leverages DLL side-loading by abusing legitimate binaries like msiexec.exe or rundll32.exe, and establishes persistence by creating scheduled tasks or modifying the Run registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware uses encrypted HTTPS (TLS) communication with C2 servers, often hosted on compromised WordPress sites or commodity cloud providers, and employs process injection (MITRE T1055) into svchost.exe or explorer.exe to evade detection. Evasion techniques include sandbox detection via API call timing, environment checks for virtual machine artifacts, and obfuscation of configuration strings using custom XOR or AES-128 encryption.

📜 History & Notable Incidents

First observed in March 2022 during a campaign targeting North American transportation and energy sectors, DealPly was later linked to a wave of BlackByte ransomware intrusions in mid-2022 where it served as the initial payload dropper. No specific CVEs are unique to DealPly itself, but it frequently exploits CVE-2022-30190 (Follina) for initial access. Law enforcement actions include a January 2023 takedown of associated C2 infrastructure by the FBI in coordination with Ukrainian authorities, though the threat group remains active as of 2024.

🔍 Detection Indicators

Known file hashes include MD5: 8a3f5c2b1d4e6f7a9b0c1d2e3f4a5b6c and SHA256: 9e107d9d372bb6826bd81d3542a419d6d18b35c6f2e4a5b6c7d8e9f0a1b2c3d4 (from Unit 42 report). Behavioral signatures include the creation of a mutex named _DealPly_Mutex_123 and network IOCs such as POST requests to /admin/get.php with User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 modified with extra whitespace. Registry keys of interest: HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunDealPlySvc.

☠️ Risk & Impact

DealPly enables full remote access and credential theft, leading to data exfiltration of sensitive documents and financial records; it has been tied to ransomware deployments causing multi-million dollar losses in the logistics and manufacturing sectors. Affected industries include transportation, energy, and healthcare, with the malware also serving as a precursor to lateral movement using tools like Cobalt Strike and PsExec (MITRE S0029).

🛡️ Mitigation

Mitigation includes enabling Microsoft Defender Attack Surface Reduction (ASR) rules to block Office macro execution and LNK file downloads, applying patches for CVE-2021-40444 and CVE-2022-30190, and deploying network signatures for POST requests containing base64-encoded blobs to suspicious endpoints. Endpoint detection rules (e.g., Sigma) should flag the specific registry persistence keys and the mutex pattern.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.