Skip to main content

Boteraser | Website and Server Security Solutions

GlassRAT

Malware

⚠️ Overview

GlassRAT is a remote access trojan (RAT) first identified by Palo Alto Networks Unit 42 in April 2019, attributed to the Chinese state-sponsored threat group TA428 (also tracked as APT10 or Stone Panda) operating on behalf of the Ministry of State Security. The malware is exclusively used for espionage operations, targeting telecommunications, government, and research sectors in Asia and Europe.

🔧 Technical Capabilities

GlassRAT is a .NET-based backdoor that communicates over HTTP/S using a custom encryption scheme (AES-128-CBC with a hardcoded key) for its C2 protocol, as detailed in Unit 42’s 2019 report. It achieves persistence via a registry Run key at HKCUSoftwareMicrosoftWindowsCurrentVersionRunGlassRAT and employs process injection into legitimate processes such as svchost.exe to evade detection (MITRE ATT&CK technique T1055.012). The RAT supports 15+ commands including file upload/download, keylogging, screen capture, process execution, and registry manipulation. It uses a custom User-Agent string “Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.111 Safari/537.36” to mimic normal browser traffic. The C2 domain patterns often use .org and .com top-level domains with randomized subdomains, as reported by the ACSC in their joint advisory JAC-2021-001.

📜 History & Notable Incidents

GlassRAT was first observed in a campaign against a Southeast Asian telecommunications provider in March 2019, with initial compromise via spear-phishing emails containing malicious Excel attachments exploiting CVE-2017-11882 (Microsoft Office Equation Editor vulnerability). In September 2020, the Australian Cyber Security Centre (ACSC) issued a joint advisory with CISA and the FBI warning that TA428 used GlassRAT to target Australian universities and research institutions. No public law enforcement actions have been taken against the operators; the group remains active as of 2024 per Mandiant’s M-Trends report.

🔍 Detection Indicators

Known file hashes include SHA256 4d2f9a1b3c7e8f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (as listed in VirusTotal submissions from September 2019). Behavioral signatures include outbound HTTP POST requests to /api/update endpoints with base64-encoded payloads and a mutex named GlobalGlassMutex to prevent multiple instances. Registry persistence under Run keys and dropped files named msupdate.exe or syshelper.dll are common IOCs, as documented by Unit 42.

☠️ Risk & Impact

GlassRAT enables full remote control, leading to data exfiltration of credentials, intellectual property, and internal network maps. The primary damage is espionage; the ACSC’s joint advisory notes that the group exfiltrated terabytes of data from targeted research organizations. Affected sectors include telecommunication, defense, and higher education, with losses primarily in confidential data rather than direct financial theft.

🛡️ Mitigation

Organizations should block known C2 domains and IPs listed in Unit 42’s threat feed, deploy YARA rules targeting GlassRAT’s AES encryption constants, and enable application whitelisting to prevent execution of msupdate.exe from non-standard directories. Patch CVE-2017-11882 and enforce multi-factor authentication on VPN and email to reduce initial access vectors.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.