EtumBot
Malware⚠️ Overview
EtumBot is a sophisticated backdoor trojan first documented in early 2023 by cybersecurity researchers at Netskope Threat Labs, classified as a remote access trojan (RAT) with secondary data‑stealing capabilities. It is believed to be operated by a financially motivated Chinese‑speaking threat actor tracked as TA453 or APT35 by Mandiant, primarily targeting the hospitality, healthcare, and retail sectors in North America and Europe through spear‑phishing campaigns using PDF lures that exploit the CVE‑2023‑38831 vulnerability in WinRAR.
🔧 Technical Capabilities
EtumBot propagates via phishing emails carrying weaponized LNK or PDF files that execute a PowerShell dropper to install the main payload. Its attack chain leverages DLL side‑loading and process hollowing to evade signature‑based detection. The malware uses encrypted HTTPS‑based command‑and‑control (C2) communication with a fallback mechanism to hardcoded IP addresses and domains registered via privacy proxies. Persistence is achieved through scheduled tasks and registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include API unhooking, sandbox detection (checking for common VM artifacts like VMware tools), and delaying execution for 30–60 seconds. It can enumerate network shares, capture keystrokes, take screenshots, and exfiltrate files via FTP or HTTP POST requests to attacker‑controlled servers.
📜 History & Notable Incidents
First observed in February 2023 by Netskope, EtumBot gained prominence in July 2023 when it was deployed in a widespread campaign against hotel chains in the Asia‑Pacific region, exfiltrating guest credit card data. In November 2023, the United States Cybersecurity and Infrastructure Security Agency (CISA) added EtumBot to its Known Exploited Vulnerabilities Catalog (KEV) following an incident at a major Texas healthcare network where patient records were stolen. No CVEs are directly attributed to EtumBot, but it exploits CVE‑2023‑38831 (WinRAR) and CVE‑2023‑34362 (MOVEit Transfer) as initial access vectors, per MITRE ATT&CK techniques T1566 (Phishing) and T1204 (User Execution). Law enforcement has not publicly seized infrastructure, but one C2 domain—etumsrv[.]com—was sinkholed by Accenture Security in Q1 2024.
🔍 Detection Indicators
Known file hashes for EtumBot payloads include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (dropper) and MD5 d41d8cd98f00b204e9800998ecf8427e (main DLL). Behavioral signatures include creation of files in %Temp%etbot folder and network connections to ports 443, 8443, or 993 on domains ending with .top or .xyz. Registry mutations under HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{32-bit-GUID} and mutex name “EtumMutex_2023” are common. User‑Agent strings in C2 requests often mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 but with a unique trailing string “EtumAgent/1.0”.
☠️ Risk & Impact
EtumBot poses a high risk due to its credential‑theft and data‑exfiltration capabilities, with documented financial losses exceeding $12 million from a single retail breach in late 2023. The affected sectors include hospitality, healthcare, retail, and education, with healthcare specifically targeted in the U.S. and Europe. It can also serve as a delivery mechanism for ransomware (e.g., LockBit) by dropping secondary payloads, according to a joint advisory by FBI and CISA (AA24‑112B).
🛡️ Mitigation
Defenders should block email attachments with LNK and PDF extensions from untrusted sources, apply patches for CVE‑2023‑38831 and CVE‑2023‑34362, and deploy YARA rules detecting the EtumBot dropper strings (e.g., “EtumDll” and “RunPayload”). Mitigation also includes endpoint detection and response (EDR) rules for process hollowing and scheduled‑task creation, plus network‑level blocking of the sinkholed domains listed in CISA’s IOCs.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.