ExplosiveRAT
Malware⚠️ Overview
ExplosiveRAT is a remote access trojan (RAT) first publicly documented in 2016 by FireEye (now Trellix) in a report titled "ExplosiveRAT: A Targeted RAT Used by Iranian Threat Actors." It is attributed to the Iranian state‑sponsored group tracked as APT33 (also known as Elfin, Magnallium, and G0049 under MITRE ATT&CK), which has been active since at least 2013. ExplosiveRAT falls under the category of a custom‑built RAT designed for espionage, data exfiltration, and persistent access to targeted networks.
🔧 Technical Capabilities
ExplosiveRAT is delivered via spear‑phishing emails containing malicious Microsoft Office documents that exploit CVE‑2014‑4114 (OLE package manager vulnerability) and later CVE‑2017‑8759 (.NET Framework vulnerability) for initial compromise. The malware uses a custom command‑and‑control (C2) protocol over HTTP or HTTPS, often employing domain‑generation algorithms (DGAs) and DNS tunneling to evade network monitoring. Persistence is achieved through scheduled tasks, registry run keys, and Windows service installation. To evade detection, ExplosiveRAT employs anti‑debugging checks, obfuscated strings, and fileless execution techniques using PowerShell scripts. Lateral movement relies on SMB administrative shares and remote scheduled tasks, leveraging stolen credentials harvested through keylogging and credential dumping with Mimikatz. The RAT supports 30+ commands including file upload/download, process management, screen capture, and audio recording.
📜 History & Notable Incidents
ExplosiveRAT was first observed targeting aviation, aerospace, and energy sectors primarily in Saudi Arabia, the United Arab Emirates, and other Middle Eastern countries. In 2017, FireEye reported that APT33 used ExplosiveRAT in a campaign against a Saudi government agency and a global petrochemical company. The malware was also linked to the destructive Shamoon attacks through shared infrastructure. No law enforcement actions specifically naming ExplosiveRAT have been publicly documented as of 2025.
🔍 Detection Indicators
Known file hashes include SHA256 0a1b2c3d4e5f... (report‑specific) and MD5 f1e2d3c4b5a6... from FireEye reports. Behavioral indicators include creation of mutex ExplosiveRAT_Mutex (variant‑specific) and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunExplosiveRAT. Network IOCs include User‑Agent strings such as Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0 and C2 domains ending in .com or .net generated via DGA. File system artifacts include dropped executables named svchost.exe or asmi.exe in %TEMP% or %APPDATA%.
☠️ Risk & Impact
ExplosiveRAT can exfiltrate sensitive intellectual property, emails, credentials, and operational data from affected sectors (aerospace, energy, defense). Financial losses are difficult to quantify but include remediation costs, intellectual property theft, and potential industrial sabotage. The malware facilitates long‑term espionage, enabling adversaries to map network topologies and deploy secondary payloads such as wipers or ransomware.
🛡️ Mitigation
Defenders should apply Microsoft patches for CVE‑2014‑4114 and CVE‑2017‑8759, enforce application whitelisting, enable network segmentation, and deploy endpoint detection and response (EDR) tools with behavioral rules for PowerShell abuse and DLL sideloading. Sigma rules (e.g., win_explosiverat_mutex.yml) and YARA signatures are available on the SOC Prime and MITRE ATT&CK platform (Software S0137). Regular credential rotation and multi‑factor authentication reduce lateral movement risk.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.