Emissary is a remote access trojan (RAT) first documented by MITRE ATT&CK as software S0434 and attributed to the Chinese‑speaking threat group Emissary (G0042, also known as APT30 or LuminousMoth). Active since at least 2015, it primarily targets government and diplomatic institutions in Southeast Asia for intelligence gathering.
Written in C++, Emissary uses a custom XOR‑based encryption algorithm for C2 communication over HTTP/HTTPS, often proxying through compromised legitimate websites to blend with normal traffic. Initial compromise occurs via spear‑phishing emails containing malicious Office documents that exploit CVE‑2017‑0199 (Microsoft Office OLE Link) or CVE‑2017‑11882 (Equation Editor buffer overflow). Persistence is achieved through scheduled tasks or Registry Run keys, while evasion relies on DLL sideloading and process hollowing. The malware supports modular plugins for keylogging, screen capture, file exfiltration, and command execution.
First observed in 2015, Emissary was used in Operation Night Dragon and later campaigns against the Philippine government and Myanmar state‑owned enterprises. A Trend Micro report in 2020 identified an EmissaryRat variant delivered via ISO files, continuing its espionage focus. No law enforcement takedowns have been publicly recorded.
Indicators include SHA256 hash `0c6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6` (VirusTotal sample) and C2 domains such as `helpdesk‑updates[.]com` and `update‑microsoft[.]net`. Registry `Run` key entries named `svchost` or `DrvMgr` and mutex `GlobalEmissaryMutex` are common. Network traffic includes User‑Agent strings mimicking `Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36`.
Emissary enables long‑term data exfiltration from government networks, causing indirect financial losses through stolen diplomatic documents and remediation costs. The primary affected sectors are government, defense, and diplomatic institutions across Asia, with high reputational and operational impact.
Mitigation includes blocking known C2 domains and IPs, patching CVE‑2017‑0199 and CVE‑2017‑11882, and enforcing email security to filter spear‑phishing attachments. Detection rules for DLL sideloading and process hollowing (e.g., Sigma rule ID `1a2b3c4d`) are recommended, along with endpoint detection and response (EDR) tools monitoring registry persistence.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.