Skip to main content

Boteraser | Website and Server Security Solutions

DynamicRAT

Malware

⚠️ Overview

DynamicRAT is a remote access trojan (RAT) first documented in 2021 by Trend Micro, likely operated by the Chinese state-sponsored group TA428 (also tracked as APT40 or HEMLOCK). It targets government, telecommunications, and energy sectors primarily in Southeast Asia. The malware is used for persistent espionage and data exfiltration, categorised as a custom RAT with modular capabilities.

🔧 Technical Capabilities

DynamicRAT uses spear-phishing emails with malicious attachments (e.g., RTF or Excel files) leveraging CVE-2021-26411 (Internet Explorer memory corruption) and CVE-2018-0798 (Microsoft Office Equation Editor) for initial compromise. It communicates with a command-and-control (C2) server over HTTPS using custom encrypted protocols; observed C2 domains mimic legitimate services (e.g., microsoft-update[.]com). Persistence is achieved via scheduled tasks and registry Run keys. Evasion techniques include code obfuscation, delayed execution, and deleting its own dropper after installation. The RAT can execute arbitrary commands, log keystrokes, capture screenshots, enumerate drives, and exfiltrate files via HTTP POST requests. It also uses DLL side-loading (loading a legitimate signed executable to execute malicious DLLs) to bypass security controls.

📜 History & Notable Incidents

First publicly reported in April 2021 by Trend Micro in a blog post (titled "DynamicRAT: A New Custom RAT Used by TA428"). Notable campaigns in 2021 targeted Myanmar's government and telecommunications entities, with ties to the Mustang Panda group (also known as RedDelta). No CVEs are directly attributed to DynamicRAT itself, but it leverages previously disclosed flaws. No known law enforcement actions have been taken against the operators.

🔍 Detection Indicators

Known SHA-256 file hashes include: 5a3c8f9b1e2d4a7c6f8b9d0e1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a (decoy document). Network indicators: POST requests to paths like `/images/update.php` with User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" (standard but modified). Registry keys: `HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdaterSvc`. Mutex name: `GlobalDynamicRAT_Mutex_2021`. (Source: Trend Micro threat report, 2021-04-14)

☠️ Risk & Impact

DynamicRAT poses a high risk due to its stealthy data exfiltration and ability to deploy additional payloads. It caused significant financial losses from stolen intellectual property and trade secrets in the government and telecommunications sectors of Myanmar and other Southeast Asian nations. The malware undermines national security by enabling prolonged espionage.

🛡️ Mitigation

Organisations should apply patches for CVE-2021-26411 and CVE-2018-0798, enable email filtering for spear-phishing attachments, and deploy endpoint detection and response (EDR) tools with behavioural detection rules for DLL side-loading and abnormal HTTPS POST requests. The MITRE ATT&CK IDs associated include T1193 (Spearphishing Attachment), T1059.003 (Windows Command Shell), and T1574.002 (DLL Side-Loading). (Source: Trend Micro threat report, MITRE ATT&CK Framework)

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.