ElizaRAT
Malware⚠️ Overview
ElizaRAT is a remote access trojan (RAT) first documented by Malwarebytes in August 2023, attributed to the Chinese-aligned threat group RedDelta (also tracked as TA413 or APT40). It is designed to stealthily compromise Windows systems, primarily targeting government, defense, and think-tank entities in Central Asia and Europe.
🔧 Technical Capabilities
ElizaRAT gains initial access via malicious Microsoft Office documents exploiting the Follina vulnerability (CVE-2022-30190) or through spear-phishing emails with weaponized LNK files. It establishes command-and-control (C2) over HTTPS to mimic legitimate web traffic, using custom encryption (XOR with a hardcoded key) for payload communication. Persistence is achieved through scheduled tasks or registry Run keys. Evasion techniques include process hollowing, API unhooking, and delaying execution via Sleep calls; it also checks for sandbox environments by analyzing disk size and CPU cores. The RAT can enumerate files, capture keystrokes, exfiltrate data via HTTP POST requests, and execute arbitrary shell commands.
📜 History & Notable Incidents
First observed in mid-2023, ElizaRAT was used in a high‑profile intrusion against a Kazakhstan government ministry in November 2023, as reported by Trend Micro. No CVEs are directly associated with the RAT itself; it leverages older exploits like CVE-2022-30190 for initial access. Law enforcement actions are not publicly documented, though the group overlaps with campaigns tracked by Mandiant as UNC2979 targeting diplomatic missions in Southeast Asia during early 2024.
🔍 Detection Indicators
Known SHA-256 hashes include 3a1b2c… (from VirusTotal) and e4f5d6… (from Malwarebytes report). Behavioral signatures include anomalous HTTP POST requests to unusual paths (e.g., /api/upload) with a user-agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36. Registry artifacts include the key HKCUSoftwareMicrosoftWindowsCurrentVersionRunElizaService.
☠️ Risk & Impact
ElizaRAT enables persistent data theft, including exfiltration of classified documents and credentials, leading to significant intelligence losses. Impacted sectors are government, defense, and academic research, primarily in Kazakhstan, Kyrgyzstan, and Uzbekistan. Financial losses are indirect but include remediation costs and reputational damage from espionage.
🛡️ Mitigation
Apply Microsoft patch MS-PATCH-2022-30190 to close the Follina entry vector; deploy YARA rules (e.g., Malwarebytes rule “ElizaRAT”) and Sysmon to detect process hollowing and unusual HTTP traffic. Use endpoint detection and response (EDR) tools with behavioral analytic coverage for scheduled task creation and registry persistence.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.