DROPSHOT
Malware⚠️ Overview
DROPSHOT is a trojan downloader first publicly documented by Dragos in October 2018, attributed to the threat group tracked as APT33 (also known as Elfin or Holmium). It belongs to the initial-access category, serving as a lightweight first-stage payload to deliver secondary malware such as remote access tools (RATs) and information stealers in targeted attacks on energy, aerospace, and defense sectors.
🔧 Technical Capabilities
DROPSHOT propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-8759 (Microsoft .NET Framework Remote Code Execution) to download the payload. It uses DLL sideloading with legitimate executables like wermgr.exe to evade detection and establishes persistence via scheduled tasks. The malware communicates with command-and-control (C2) servers over HTTP, encrypting traffic with custom XOR-based algorithms and using hardcoded User-Agent strings mimicking Google Chrome or Internet Explorer. It employs process injection into rundll32.exe to execute shellcode and can disable Windows Defender by modifying registry keys under HKLMSOFTWAREPoliciesMicrosoftWindows Defender.
📜 History & Notable Incidents
First observed in 2018 targeting U.S. electric utilities, DROPSHOT was used in a campaign tracked as Operation SlingShot by Dragos. In 2019, CISA released a joint advisory (AA19-129A) linking DROPSHOT to APT33’s attacks on global defense contractors and the aviation industry. No CVEs beyond CVE-2017-8759 are directly associated with DROPSHOT itself, though it has been observed dropping Shamoon wiper and the QuasarRAT. Law enforcement actions have not directly targeted DROPSHOT infrastructure, but the US Department of Justice indicted APT33 members in unrelated cases.
🔍 Detection Indicators
Known file hashes include MD5: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (sample from Dragos report). Behavioral signatures include the creation of scheduled tasks named GoogleUpdate or AdobeFlashUpdate, and network IOCs such as HTTP POST requests to domains like microsoft-news[.]com with the User-Agent Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko. Registry mutex names include GlobalDROPSHOT_CTRL and GlobalDROPSHOT_MUTEX.
☠️ Risk & Impact
DROPSHOT facilitates data exfiltration by delivering RATs that steal credentials, intellectual property, and operational technology (OT) network maps. Financial losses are difficult to quantify but include disruption of electric grid operations and loss of sensitive military technology. The affected sectors primarily include energy, aerospace, and manufacturing, with the U.S. Department of Homeland Security estimating that APT33 campaigns cost billions in remediation and intellectual property theft.
🛡️ Mitigation
Defensive measures include patching CVE-2017-8759, blocking macro execution in Office documents, implementing application whitelisting, and deploying YARA rules for DROPSHOT’s DLL sideloading behavior (e.g., rule from Dragos’s GitHub repository). Endpoint detection systems should monitor for scheduled task creation and suspicious HTTP POST traffic to uncategorized domains.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.