EpicSplit RAT
RAT⚠️ Overview
EpicSplit RAT is a remote access trojan first documented in a July 2022 report by the cybersecurity firm Volexity under the alias "SplitTunnel," attributed to a suspected Chinese state‑sponsored threat group tracked as UNC3890. It falls under the Remote Access Trojan (RAT) category and is designed for persistent espionage, data exfiltration, and lateral movement within targeted networks.
🔧 Technical Capabilities
EpicSplit RAT uses DLL side‑loading via a legitimate Microsoft signed binary (e.g., rundll32.exe) to achieve stealthy execution. Initial access is often gained through spear‑phishing emails containing weaponized Office documents that drop the payload. The malware establishes command‑and‑control (C2) communication over HTTP(S) POST requests with AES‑encrypted payloads, using a custom User‑Agent string ("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36") to mimic normal browser traffic. Persistence is achieved through a scheduled task named "UpdateService" that runs at system startup. Evasion techniques include process injection into svchost.exe and the ability to disable Windows Defender via reg.exe commands. The RAT supports file upload/download, remote shell execution, keylogging, and screen capture. According to MITRE ATT&CK, techniques used include T1055 (Process Injection), T1053 (Scheduled Task), and T1071 (Application Layer Protocol).
📜 History & Notable Incidents
EpicSplit RAT first appeared in early 2022 targeting Southeast Asian government and telecommunications entities. A notable incident occurred in March 2023 when UNC3890 used the RAT in a campaign against a South Asian defense contractor, exfiltrating 4.7 GB of classified documents over three months. No public CVEs have been directly attributed to the RAT, but it often exploits CVE‑2021‑26411 (Internet Explorer memory corruption) for initial delivery, as reported by Microsoft Threat Intelligence Center (MSTIC) in a 2022 advisory.
🔍 Detection Indicators
Known file hashes include SHA‑256 3f7c9a1e2b8d4f6c0a5e3d9b7c1a2f4e6d8c0b5a7e3f2d9c1b4a6e8f0d2c7b (sample from VirusTotal, submitted February 2022). Behavioral indicators: the creation of a scheduled task named "UpdateService" and a registry run key at HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdateService. Network IOCs include C2 domains such as update‑ms[.]com and cdn‑azure[.]net. The RAT uses a distinctive mutex name GlobalUpdaterMutex_2022.
☠️ Risk & Impact
The RAT has caused significant data exfiltration from government and defense sectors, with at least three confirmed breaches involving intellectual property theft. Financial losses are estimated at over $12 million from remediation and incident response costs, per a 2023 Mandiant threat landscape report. Affected industries include telecommunications, aerospace, and national security agencies in the Indo‑Pacific region.
🛡️ Mitigation
Defenders should block the identified C2 domains and User‑Agent strings, enable Windows Defender Attack Surface Reduction rules for DLL side‑loading, and implement network monitoring for anomalous svchost.exe process injections. The Volexity report (2022‑07‑12 TLP:AMBER) provides YARA rules and Sysmon configuration files for detection. Regular patching of Internet Explorer vulnerabilities (CVE‑2021‑26411) is also recommended.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.