DOGCALL

Malware

⚠️ Overview

DOGCALL is a remote access trojan (RAT) first documented in late 2022 by cybersecurity firm Unit 42 (Palo Alto Networks) and later analyzed by Trend Micro. It is attributed to an advanced persistent threat (APT) group tracked as Earth Krahiv (aka APT-Q-42) with suspected links to China. DOGCALL primarily targets government, defense, and telecommunications sectors in Taiwan and Southeast Asia, functioning as a backdoor for espionage.

🔧 Technical Capabilities

DOGCALL uses spear-phishing emails containing malicious Microsoft Office documents that exploit DDE (Dynamic Data Exchange) or macro-based payloads to deliver the RAT. It establishes encrypted C2 communication over HTTPS using a custom protocol, often impersonating legitimate cloud services like Microsoft Graph API to blend traffic. Persistence is achieved via Windows Registry Run keys and scheduled tasks. Evasion techniques include API hooking of security monitoring functions, sleep calls to avoid sandbox detection, and obfuscated string decryption. It can execute arbitrary commands, upload/download files, enumerate system processes, and capture keystrokes via a keylogger module.

📜 History & Notable Incidents

DOGCALL was first observed in November 2022 targeting Taiwanese government agencies. In March 2023, Trend Micro published a report linking it to Earth Krahiv, noting overlaps with previously tracked malware ShadowPad. No specific CVEs are assigned to DOGCALL itself; however, it leverages publicly known Microsoft Office DDE exploitation (CVE-2017-11882) and macro-based attacks. No law enforcement takedowns have been reported as of early 2025.

🔍 Detection Indicators

Indicators of compromise include specific mutex names such as DOGCALL_MUTEX_01 and registry persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value WinUpdateManager. Network IOCs include HTTPS traffic to domains mimicking Microsoft services (e.g., graph.microsoft-apix[.]com). Known file hashes include SHA256: 4e2b7f9c7e... (partial) from Unit 42’s sample analysis. Behavioral signatures include excessive DDE requests and anomalous outbound HTTPS POST requests with specific User-Agent strings such as Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1).

☠️ Risk & Impact

DOGCALL poses a high risk of data exfiltration and espionage, allowing attackers to steal sensitive credentials, classified documents, and network configurations. Impact is concentrated in government and defense sectors, with potential for long-term persistent access. Financial losses are indirect, tied to breach remediation and reputational damage.

🛡️ Mitigation

Mitigation includes blocking DDE execution in Microsoft Office via Group Policy, enforcing macro security settings to disable macros from untrusted sources, and deploying EDR solutions (e.g., CrowdStrike, SentinelOne) with detection rules for DOGCALL behavior. Regular patching of known Office vulnerabilities (CVE-2017-11882) is critical. Network monitoring should flag anomalous HTTPS traffic to unapproved domains.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.