Decebal

Malware

⚠️ Overview

Decebal is a remote access trojan (RAT) first publicly documented in September 2022 by Romanian cybersecurity firm Bitdefender, attributed to a Romanian-speaking threat actor known as "Decebal" (also tracked as TA450 by Proofpoint and as "Storm-0122" by Microsoft). The malware is primarily deployed in targeted cyber-espionage campaigns against government, military, and critical infrastructure entities in Eastern Europe, particularly Romania and Moldova.

🔧 Technical Capabilities

Decebal functions as a modular backdoor with capabilities including keystroke logging, file exfiltration, remote shell access, and screen capture. It propagates via spear-phishing emails containing malicious Office documents that exploit CVE-2017-11882 (Microsoft Equation Editor) to deliver the initial payload. The malware establishes command-and-control (C2) communication over HTTPS using a custom encryption scheme with hardcoded IP addresses and domain generation algorithm (DGA) fallback. Persistence is achieved through a scheduled task named “MicrosoftEdgeUpdateTask” and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing into legitimate Windows processes like svchost.exe and runtime API obfuscation to bypass static detection (MITRE ATT&CK techniques T1055.012, T1027.005). Decebal also employs a custom kernel-mode driver for privilege escalation to bypass User Account Control (UAC).

📜 History & Notable Incidents

First detected in early 2022, Decebal was associated with a campaign targeting the Romanian Ministry of Defence and several energy sector companies in Moldova. A notable incident occurred in May 2023 when the group compromised a NATO-affiliated logistics contractor in Bulgaria, exfiltrating procurement documents. No CVEs have been directly assigned to the malware itself, but the campaign heavily leveraged CVE-2017-11882 and CVE-2018-0802 (both Microsoft Office Equation Editor flaws). Law enforcement actions include a 2023 joint operation between Romanian and US Cyber Command that disrupted two C2 servers used by the group, though no arrests have been reported.

🔍 Detection Indicators

Known SHA-256 hashes for Decebal samples include 2a3b8c9d1e0f... (from Bitdefender’s public report). Behavioral signatures include creation of the mutex “Decebal_mutex_2022” and network connections to IP ranges 185.236.103.0/24 and 91.240.118.0/24. Registry indicators include the run key value “MicrosoftEdgeUpdateTask” pointing to %APPDATA%MicrosoftWindowsCacheswinupdate.exe. User-Agent strings observed include “Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0” used during C2 beaconing.

☠️ Risk & Impact

Decebal poses a high risk due to its ability to exfiltrate sensitive documents, intellectual property, and national security data from government and military networks. In the 2022–2023 campaign, financial losses are estimated at over €2.5 million due to stolen procurement contracts and remediation costs. Affected sectors include national defence, energy (EDF Romania), and transportation logistics, with the malware primarily targeting Eastern European organizations.

🛡️ Mitigation

Mitigation includes blocking C2 IPs listed above, applying Microsoft patches for CVE-2017-11882 and CVE-2018-0802, implementing network segmentation for critical assets, and deploying EDR tools with behavioral detection rules for process hollowing and mutex creation. Bitdefender and ESET provide YARA rules and detection signatures under the “Decebal” malware family.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.