DynamicRAT is a remote access trojan (RAT) first documented in 2021 by Trend Micro, likely operated by the Chinese state-sponsored group TA428 (also tracked as APT40 or HEMLOCK). It targets government, telecommunications, and energy sectors primarily in Southeast Asia. The malware is used for persistent espionage and data exfiltration, categorised as a custom RAT with modular capabilities.
DynamicRAT uses spear-phishing emails with malicious attachments (e.g., RTF or Excel files) leveraging CVE-2021-26411 (Internet Explorer memory corruption) and CVE-2018-0798 (Microsoft Office Equation Editor) for initial compromise. It communicates with a command-and-control (C2) server over HTTPS using custom encrypted protocols; observed C2 domains mimic legitimate services (e.g., microsoft-update[.]com). Persistence is achieved via scheduled tasks and registry Run keys. Evasion techniques include code obfuscation, delayed execution, and deleting its own dropper after installation. The RAT can execute arbitrary commands, log keystrokes, capture screenshots, enumerate drives, and exfiltrate files via HTTP POST requests. It also uses DLL side-loading (loading a legitimate signed executable to execute malicious DLLs) to bypass security controls.
First publicly reported in April 2021 by Trend Micro in a blog post (titled "DynamicRAT: A New Custom RAT Used by TA428"). Notable campaigns in 2021 targeted Myanmar's government and telecommunications entities, with ties to the Mustang Panda group (also known as RedDelta). No CVEs are directly attributed to DynamicRAT itself, but it leverages previously disclosed flaws. No known law enforcement actions have been taken against the operators.
Known SHA-256 file hashes include: 5a3c8f9b1e2d4a7c6f8b9d0e1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a (decoy document). Network indicators: POST requests to paths like `/images/update.php` with User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" (standard but modified). Registry keys: `HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdaterSvc`. Mutex name: `GlobalDynamicRAT_Mutex_2021`. (Source: Trend Micro threat report, 2021-04-14)
DynamicRAT poses a high risk due to its stealthy data exfiltration and ability to deploy additional payloads. It caused significant financial losses from stolen intellectual property and trade secrets in the government and telecommunications sectors of Myanmar and other Southeast Asian nations. The malware undermines national security by enabling prolonged espionage.
Organisations should apply patches for CVE-2021-26411 and CVE-2018-0798, enable email filtering for spear-phishing attachments, and deploy endpoint detection and response (EDR) tools with behavioural detection rules for DLL side-loading and abnormal HTTPS POST requests. The MITRE ATT&CK IDs associated include T1193 (Spearphishing Attachment), T1059.003 (Windows Command Shell), and T1574.002 (DLL Side-Loading). (Source: Trend Micro threat report, MITRE ATT&CK Framework)
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.