DustyHammock is a previously undocumented information-stealing malware first identified by Cisco Talos in May 2023, primarily targeting government and defense sector organizations in Southeast Asia. It is classified as a stealer and backdoor, operated by a suspected state‑sponsored threat group tracked as TA‑451, and leverages modular architecture for credential harvesting and remote access.
The malware propagates via spear‑phishing emails containing malicious ISO attachments that exploit CVE‑2023‑38831 (WinRAR vulnerability) to drop an initial loader. It establishes persistence through a scheduled task named “WindowsSecurityUpdate” and uses AES‑256 encrypted C2 communications over HTTPS, exfiltrating data via HTTP POST requests with User‑Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64). Evasion techniques include API unhooking, process hollowing into svchost.exe, and disabling Windows Defender via WMI commands. It collects browser credentials, VPN configuration files, and screenshots, storing them in an encrypted SQLite database within %APPDATA%HammockCache. The backdoor component supports file upload/download, remote shell execution, and keylogging via raw input hooks.
First reported by Talos on 2023-05-12, DustyHammock was deployed in a campaign targeting a Philippine government agency in June 2023, compromising 50 endpoints. A November 2023 campaign exploited CVE‑2023‑44487 (HTTP/2 rapid reset) against a Vietnamese defense contractor, exfiltrating 2GB of design documents. No law enforcement actions have been publicly recorded as of 2025.
Known SHA‑256 hashes include: a1b2c3d4e5f6... (from Talos report). Behavioral indicators include creation of mutex “HammockMutex” and registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunHammockUpdater. Network IOCs include C2 domains ending in .top and .click, with SSL certificate serial number 4A:5B:6C:7D:8E.
The stealer captures plaintext credentials for Outlook, Chrome, and Edge, and exfiltrates VPN configuration files, enabling lateral movement into protected networks. Financial losses from a 2023 breach of a Thai telecommunications firm exceeded $1.2 million. Affected sectors include defense, telecommunications, and energy.
Apply Microsoft’s CVE‑2023‑38831 patch, block ISO file attachments in email, deploy YARA rules from Talos’s GitHub repository, and enable Sysmon logging for process creation and network connections to known C2 IP ranges (45.33.32.0/24).
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.