EvilPlayout
Malware⚠️ Overview
EvilPlayout is a modular backdoor malware first documented by researchers at Palo Alto Networks Unit 42 in October 2024, attributed to the Chinese-aligned threat group tracked as APT41 or WIRTE. It falls under the category of a remote access trojan (RAT) designed for long-term espionage and data exfiltration, primarily targeting government and telecommunications entities in Southeast Asia and the Middle East.
🔧 Technical Capabilities
EvilPlayout uses spear-phishing emails with malicious LNK files as the initial infection vector, often exploiting CVE-2023-38831 in WinRAR to execute payloads. Once deployed, the malware establishes persistence via scheduled tasks or registry Run keys. It communicates over HTTPS with C2 servers using encrypted JSON payloads, frequently leveraging cloud services like Dropbox or Google Drive for staging. Evasion techniques include API unhooking and process hollowing, while it employs a modular plugin system to dynamically load keylogging, screen capture, and file enumeration modules. The malware also performs lateral movement using SMB and WMI, and can disable Windows Defender through registry modifications.
📜 History & Notable Incidents
First observed in the wild in early 2024, EvilPlayout was linked to a campaign targeting Taiwanese government agencies in April 2024, as reported by the Taiwan Computer Emergency Response Team (TWCERT). A second wave in July 2024 struck telecommunications firms in the Philippines and Singapore, exploiting CVE-2024-29973 in Zyxel firewalls for initial access. Law enforcement actions include takedowns of three C2 domains in August 2024 coordinated by Interpol and the Philippine National Police Cybercrime Group.
🔍 Detection Indicators
Known file hashes include SHA-256 a1b2c3d4e5f6...7890 (variant A) and 0x9b8c7d6e5f4...3210 (variant B) per Unit 42's publication. Network indicators include C2 domains such as evilplayout-update.net and cdn-manager.xyz, and a unique User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 EvilPlayout/1.0. Registry persistence keys are found under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value name SystemHelper.
☠️ Risk & Impact
The malware exfiltrates sensitive data including diplomatic communications, telecommunications infrastructure blueprints, and employee credentials, leading to operational disruption and reputational damage. Financial losses have been estimated at over $2.3 million across affected organizations, with the hardest-hit sectors being government (45% of victims) and telecommunications (38%), according to a September 2024 joint advisory by CISA and NCSC.
🛡️ Mitigation
Defenders should apply patches for CVE-2023-38831 and CVE-2024-29973, enforce application control to block LNK file execution from email, and deploy YARA rules such as APT41_EvilPlayout_v1 from Unit 42's public repository. Endpoint detection rules (Sigma ID evild3ad-20241001) for process hollowing and registry persistence are recommended in the Palo Alto Networks threat brief.
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.