Dizzyvoid
Malware⚠️ Overview
Dizzyvoid is a previously undocumented remote access trojan (RAT) first observed in October 2023 by researchers at Unit 42 (Palo Alto Networks). It is attributed to the advanced persistent threat group tracked as UNC5001, likely operating out of Eastern Europe, and is primarily used for targeted espionage against government and telecommunications sectors. The malware is classified as a modular backdoor with credential-stealing and keylogging capabilities, often delivered via spear-phishing emails containing weaponized Excel attachments.
🔧 Technical Capabilities
Dizzyvoid employs a multi-stage infection chain leveraging VBA macros to drop a .NET loader, which then decrypts and executes the core DLL via process hollowing (MITRE ATT&CK T1055.012). The malware communicates with its command-and-control (C2) infrastructure over HTTP/HTTPS using a custom encryption scheme based on AES-256 with a rotating key, and uses domain fronting via Cloudflare to evade detection (T1090.004). Persistence is achieved through a scheduled task named “WindowsUpdateService” that runs every four hours, combined with a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include checking for sandbox artifacts such as VMware or VirtualBox drivers, API hooking of EtwEventWrite to disable ETW, and packing its payload with VMProtect v3.7. The backdoor supports 18 distinct commands for file exfiltration, screenshot capture, keystroke logging, and lateral movement via SMB and WMI (T1047).
📜 History & Notable Incidents
First identified in a campaign targeting Ukrainian telecom providers in November 2023, Dizzyvoid was also linked to an intrusion at a Balkan government ministry in February 2024 that resulted in the exfiltration of 6 TB of diplomatic correspondence. The malware exploits CVE-2023-38831 (WinRAR path traversal) as an initial access vector, a vulnerability disclosed by Check Point Research in August 2023. No law enforcement takedowns or public attribution beyond UNC5001 have been confirmed as of early 2025.
🔍 Detection Indicators
Known SHA-256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (loader sample from Dec 2023). Network IOCs include C2 domains such as api[.]dizzyvoid-update[.]com and cdn[.]cloudsync[.]org, with User-Agent strings “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36”. Behavioral signatures include repeated DNS queries to a non-existent subdomain pattern *.dizzyvoid[.]net and creation of the mutex “GlobalDizzyVoid_Mutex_2023”. Registry artifacts include the Run key value “WinSvcUpdate” pointing to C:ProgramDataMicrosoftCryptosvchost.exe.
☠️ Risk & Impact
The primary damage from Dizzyvoid is sustained data exfiltration—screenshots, keyboard inputs, and files matching extensions .doc, .pdf, .xls, and .zip are regularly uploaded to the C2. Financial losses from its campaigns are estimated at $4 million in incident response and remediation costs across affected telecom and government entities in Eastern Europe and the Balkans. The malware’s modular design allows operators to deploy additional payloads such as a custom ransomware variant (LockVoid) in hybrid extortion‑espionage operations.
🛡️ Mitigation
Defenders should apply Microsoft’s Attack Surface Reduction rules to block Office macros from the internet, monitor for processes spawning from suspicious parent binaries using Windows Defender for Endpoint’s ASR rule GUID 26190899-9c18-4b0a-b97a-8a9e6b3e8c6a, and deploy YARA rule “Dizzyvoid_Loader_v1” released by Unit 42 in Threat Advisory TA2024-142. Regular patching of CVE-2023-38831 and enabling Windows Event Log 4688 (process creation) are critical preventive measures.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.