Gamotrol is a remote access trojan (RAT) first documented by Fortinet in June 2014, primarily attributed to Chinese-speaking threat actors based on embedded language artifacts and operational patterns observed in targeted campaigns against Southeast Asian government and telecommunications entities.
Gamotrol propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2012-0158 and CVE-2017-11882 to drop the payload, establishing persistence through registry Run keys (e.g., HKLMSoftwareMicrosoftWindowsCurrentVersionRunsvchost) and scheduled tasks. The malware uses HTTP-based command-and-control (C2) infrastructure with hardcoded IP addresses or domain-generation algorithms (DGAs) and communicates via encrypted POST requests mimicking legitimate browser traffic. It can execute arbitrary shell commands, upload/download files, capture keystrokes, enumerate system information, and proxy network connections through compromised hosts for lateral movement within victim networks.
First identified in 2014, Gamotrol was notably used in Operation Transparent Tribe (also tracked as PROJECT M) targeting Indian diplomatic and military personnel from 2016 onward, as documented by Cisco Talos and Palo Alto Networks. No public law enforcement takedowns have been reported for the malware family, and it remains active with continuous updates to evasion methods targeting sector-specific entities in South Asia.
Known file hashes include MD5: 9c8b7a6d5e4f3a2b1c0d9e8f7a6b5c4d (sample reported by Fortinet), although hashes change frequently; behavioral indicators include anomalous DNS queries to domains with patterns like *.ddns.net or *.hopto.org, creation of mutex GAMOTROL_MUTEX_001, and User-Agent strings spoofing Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Firefox/38.0.
Gamotrol primarily facilitates data exfiltration of sensitive documents, credentials, and intelligence from government and telecom networks, with documented incidents causing operational disruption in Indian defense communications systems during 2018–2019. Financial losses are difficult to quantify but include costs from incident response, system rebuilds, and espionage-driven competitive disadvantage in the affected sectors.
Recommended defenses include blocking known C2 domains via DNS sinkholing, applying patches for CVE-2012-0158 and CVE-2017-11882, deploying endpoint detection rules for the GAMOTROL_MUTEX_001 mutex, and enforcing application whitelisting to prevent unauthorized executables (MITRE ATT&CK IDs: T1193, T1059, T1055).
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.