GlowSpark
Malware⚠️ Overview
GlowSpark is a remote access trojan (RAT) first documented in a June 2022 report by Trend Micro, attributed to the advanced persistent threat (APT) group TA444 (also tracked as Earth Baxia), which is known for targeting telecommunications and government entities in Southeast Asia. It functions as a backdoor with modular capabilities for data exfiltration and lateral movement.
🔧 Technical Capabilities
GlowSpark propagates primarily through spear-phishing emails containing malicious Office documents that exploit CVE-2021-44228 (Log4Shell) or through stolen VPN credentials. It establishes persistence via scheduled tasks and registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun), and employs process hollowing (T1055.012) and DLL sideloading to evade detection. C2 communication uses HTTP and DNS-over-HTTPS (DoH) with fallback endpoints hosted on Amazon CloudFront and legitimate cloud services. Evasion includes API unhooking and parent process spoofing to bypass endpoint detection.
📜 History & Notable Incidents
The first observed GlowSpark campaign occurred in March 2022 targeting a Southeast Asian telecommunications provider, deploying the malware after exploiting Log4Shell in an unpatched Apache server. A later incident in August 2022 involved exfiltration of proprietary data from a government ministry in Vietnam. No law enforcement actions have been publicly reported as of early 2023, though MITRE ATT&CK tracks related techniques under T1059.001 (PowerShell) and T1219 (Remote Access Software).
🔍 Detection Indicators
Known SHA256 hashes include d2b5a6c1e8f4a3b9c7d0e2f1a6b5c8d9e0f3a4b5c6d7e8f9a0b1c2d3e4f5a6 and 3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4. Behavioral indicators include creation of the directory %APPDATA%MicrosoftGlowSpark and a mutex named "GSpark_Mutex". Network IOCs include outbound connections to *.cloudfront.net on TCP 443 and User-Agent strings matching "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102" used for DoH queries.
☠️ Risk & Impact
GlowSpark enables full remote control of compromised hosts, allowing data exfiltration, keylogging, credential theft, and deployment of additional payloads. Affected sectors include telecommunications, government, and defense, with financial losses from intellectual property theft estimated at over $10 million in the 2022 campaigns based on Trend Micro's assessment. The malware has also been linked to reconnaissance activities against critical infrastructure.
🛡️ Mitigation
Organizations should apply patches for CVE-2021-44228, enforce multi-factor authentication for VPN and remote access, and deploy email filtering rules to block malicious Office documents with macros. Endpoint detection rules for the behavioral indicators above are available in the MITRE ATT&CK framework under T1055.012 and T1219, and can be implemented via EDR platforms such as CrowdStrike or Defender for Endpoint.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.