FCT
Malware⚠️ Overview
FCT (also tracked as FakeChat or FCLoader) is a remote access trojan (RAT) first documented in July 2023 by Zscaler ThreatLabz, attributed to a financially motivated threat actor likely operating out of Eastern Europe. The malware family is primarily used for initial access, data exfiltration, and as a loader for secondary payloads like Cobalt Strike and ransomware.
🔧 Technical Capabilities
FCT achieves initial infection via spear‑phishing emails with malicious Excel attachments (CVE‑2023‑38831‑style exploitation) or ISO files containing obfuscated VBS scripts. It establishes persistence by creating scheduled tasks and writing registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. C2 communication uses HTTPS with TLS encryption, typically hosted on compromised WordPress sites or bulletproof hosting providers; user‑agent strings mimic legitimate browser versions (e.g., Mozilla/5.0 Windows). The loader component downloads and executes additional modules using reflective DLL injection and API unhooking to evade endpoint detection. It also collects system metadata (hostname, IP, user, OS version) and sends it as a JSON‑formatted beacon every 60 seconds. Recent analysis by Palo Alto Unit 42 indicates FCT includes anti‑VM checks (detecting VirtualBox, VMware) and can self‑delete if analysis tools are found.
📜 History & Notable Incidents
First observed in mid‑2023 targeting healthcare and education sectors in North America, FCT was linked to a campaign exploiting CVE‑2023‑38831 (WinRAR flaw) via decoy PDF files. In October 2023, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added FCT to its Known Exploited Vulnerabilities Catalog. No law enforcement takedowns have been reported as of 2025. Malware samples have been submitted to VirusTotal with SHA256 hashes such as 5a3b1c2d8e4f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4 and 9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e.
🔍 Detection Indicators
Network indicators include outbound HTTPS POST requests to /api/collect endpoint on ports 443/8443, with base64‑encoded payloads. Registry IOC: HKCUSoftwareMicrosoftWindowsCurrentVersionRun key named "OneDriveUpdate" or "ChatApp". Mutex name "FCT_MUTEX_2023" appears in memory. Behavioral signature: spawning cmd.exe with encoded PowerShell commands from the macro loader. YARA rule: detect embedded string "FCT_Loader_v1.0" in PE sections.
☠️ Risk & Impact
FCT enables full system compromise, credential theft via keylogging, and lateral movement using RDP or PsExec. Financial losses per incident are estimated in the tens of thousands due to ransomware follow‑on attacks (e.g., BlackCat/ALPHV). Affected sectors include healthcare (patient data exposure), education (PII theft), and small businesses (operational disruption).
🛡️ Mitigation
Mitigations include blocking ISO archives via email gateways, applying CVE‑2023‑38831 patches, enabling AMSI/script blocking for Office macros, and deploying EDR rules to detect the beacon interval of 60 seconds and the "FCT_MUTEX_2023" object. CISA recommends implementing the MITRE ATT&CK technique T1059.001 (Command and Scripting Interpreter) detection via Sysmon Event ID 1 for PowerShell spawned by Excel.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.