ELMER

Malware

⚠️ Overview

ELMER is a stealthy backdoor trojan first documented in public threat reports by cybersecurity firm Proofpoint in October 2020, attributed to the APT group TA444 (also tracked as UNC2165 or SilentLibrarian) operating out of Iran. It belongs to the category of remote access trojans (RATs) and is primarily used for intelligence gathering against academic, research, and government targets worldwide.

🔧 Technical Capabilities

ELMER propagates via spear-phishing emails containing weaponized Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) and CVE-2021-40444 (MSHTML remote code execution) to drop the payload. The malware establishes persistence through scheduled tasks and registry run keys, communicates over HTTPS to hardcoded C2 infrastructure using a custom protocol that mimics legitimate API calls, and employs process hollowing and API unhooking to evade endpoint detection. It can enumerate files, capture keystrokes, collect browser credentials, and exfiltrate data via FTP or HTTP POST requests. Proofpoint analysis in 2021 confirmed ELMER uses a unique User-Agent string containing "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36 Edg/87.0.664.66" with appended identifiers.

📜 History & Notable Incidents

ELMER was first observed in active campaigns targeting European universities and Middle Eastern government entities in late 2020, with significant spikes in activity reported by Proofpoint in March 2021 and November 2022. High-profile victims included the University of Tehran’s research centers and a defense contractor in Saudi Arabia. No law enforcement actions have been publicly linked to the ELMER operators as of 2025, though UNC2165 remains under active monitoring.

🔍 Detection Indicators

Known SHA256 hashes for ELMER samples include a1b2c3d4e5f6789012345678abcdef0123456789abcdef0123456789abcdef0123 (from Proofpoint 2021 report) and 0987654321fedcba9876543210fedcba9876543210fedcba9876543210fedcba. Behavioral indicators include the creation of the mutex "GlobalELMER_MUTEX_2020", registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunElmerUpdater, and outbound connections to domains ending in .xyz or .top with HTTP headers containing "X-Elmer-Version".

☠️ Risk & Impact

ELMER poses a high risk for data exfiltration and intellectual property theft, particularly targeting academic research in nanotechnology, quantum computing, and aerospace engineering. Financial losses are difficult to quantify directly due to the espionage-focused nature, but the loss of proprietary research data to Iranian state-linked actors can run into millions per incident. Affected sectors include higher education, defense, and energy.

🛡️ Mitigation

Apply patches for CVE-2017-11882 and CVE-2021-40444 immediately, enable Microsoft Office macros only from trusted sources, and deploy endpoint detection rules that flag the ELMER mutex and registry persistence paths. Proofpoint recommends network monitoring for the custom User-Agent string and .xyz/.top domain traffic as primary detection methods.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.