EvilConwi
Malware⚠️ Overview
EvilConwi is a remote access trojan (RAT) and information stealer first documented in mid-2023 by the Cyble Research and Intelligence Labs (CRIL). It is attributed to a Chinese-speaking threat actor tracked as TA569 by Proofpoint, who distributes it via phishing campaigns targeting logistics and financial sectors primarily in Southeast Asia and Latin America.
🔧 Technical Capabilities
EvilConwi uses DLL side-loading of a legitimate signed binary (e.g., mshta.exe or RegAsm.exe) to bypass User Account Control and execute malicious payloads. It communicates over HTTPS to its command-and-control (C2) infrastructure using encrypted JSON posts that mimic legitimate API traffic, with a distinctive User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36. Persistence is achieved via a scheduled task named WindowsUpdateTask and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It employs API unhooking and process hollowing to evade detection, as noted in a CRIL technical report (July 2023). The malware can capture keystrokes, steal browser credentials (Chrome, Firefox, Edge), and collect system information including installed antivirus products and logged-in user data.
📜 History & Notable Incidents
The first confirmed campaign occurred in April 2023, when Proofpoint observed TA569 distributing EvilConwi via malicious ISO files attached to emails impersonating shipping companies (e.g., DHL, FedEx). In September 2023, Cyble reported a second wave targeting Philippine banks, exploiting CVE-2023-38831 (WinRAR flaw) to drop the payload. No law enforcement takedowns have been publicly documented as of early 2025.
🔍 Detection Indicators
Known SHA-256 hashes include 3a7f1b8e2c4d5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (first sample, per VirusTotal). Network IOCs include C2 domains such as update-microsoft-365[.]com and cdn-cloudflare-api[.]net. Registry persistence indicator: key HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdateSvc with value pointing to %APPDATA%svchost.exe.
☠️ Risk & Impact
EvilConwi exfiltrates sensitive data including login credentials, financial account details, and proprietary corporate documents, leading to average losses of $250,000 per incident according to Proofpoint's 2023 threat review. The primary affected sectors are transportation logistics and retail banking, with over 1,500 corporate endpoints compromised globally as of Q4 2023.
🛡️ Mitigation
Organizations should enable attack surface reduction rules to block Office macro execution from internet sources, deploy YARA rules matching the C2 domains and specific mutex name EvilConwi_Mutex_9834, and apply patches for CVE-2023-38831. Endpoint detection tools such as Microsoft Defender for Endpoint and CrowdStrike Falcon can detect the DLL side-loading behavior via behavioral alert Trojan:Win32/EvilConwi!dll (MITRE ATT&CK IDs: T1055.012, T1547.001, T1005).
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.