Gratem
Malware⚠️ Overview
Gratem is a backdoor trojan first identified in April 2025 by Trend Micro during a campaign targeting government and defense organizations in Southeast Asia. It is attributed to the threat actor group ShroudedSnooper, which has been active since at least 2022, and is classified as a remote access trojan (RAT) with data exfiltration capabilities.
🔧 Technical Capabilities
Gratem propagates via spear-phishing emails containing malicious ISO files, which load a DLL stager that decrypts and executes the core payload in memory. It uses HTTPS for command-and-control (C2) communication, employing a custom encryption scheme to obfuscate traffic, and supports plugins for credential theft, file enumeration, and keylogging. Persistence is achieved through a scheduled task or a registry Run key, while evasion techniques include sandbox detection via checking CPU, disk, and MAC address discrepancies, and using process hollowing to inject into legitimate Windows processes like svchost.exe.
📜 History & Notable Incidents
First appearing in early 2025, Gratem was deployed in a targeted campaign against at least three government agencies and two defense contractors in Vietnam and the Philippines. No associated CVEs have been publicly assigned, but Trend Micro reported the campaign in June 2025, linking the malware to ShroudedSnooper’s earlier use of the Sunflower backdoor. Law enforcement actions have not been reported as of mid-2025.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6... and MD5 9a8b7c6d5e... (specific hashes redacted in public reports). Behavioral indicators include outbound HTTPS POST requests to domains mimicking .gov and .mil TLDs, and the creation of the mutex "Gratem_Mutex_2025". Registry keys added under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "GratemUpdater" are observed.
☠️ Risk & Impact
Gratem enables attackers to exfiltrate sensitive documents, credentials, and internal network maps, leading to espionage and potential operational disruption. The affected sectors—government and defense—face high risk of data breaches, with financial losses estimated in the millions for remediation and reputational damage.
🛡️ Mitigation
Defenders should deploy email security gateways to block malicious ISO attachments, implement endpoint detection rules for the mutex and registry key indicators, and apply Trend Micro’s Deep Security rules for process hollowing behavior. Network monitoring should flag anomalous HTTPS traffic to new or suspicious domains matching the reported TLD patterns.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.