Gratem

Malware

⚠️ Overview

Gratem is a backdoor trojan first identified in April 2025 by Trend Micro during a campaign targeting government and defense organizations in Southeast Asia. It is attributed to the threat actor group ShroudedSnooper, which has been active since at least 2022, and is classified as a remote access trojan (RAT) with data exfiltration capabilities.

🔧 Technical Capabilities

Gratem propagates via spear-phishing emails containing malicious ISO files, which load a DLL stager that decrypts and executes the core payload in memory. It uses HTTPS for command-and-control (C2) communication, employing a custom encryption scheme to obfuscate traffic, and supports plugins for credential theft, file enumeration, and keylogging. Persistence is achieved through a scheduled task or a registry Run key, while evasion techniques include sandbox detection via checking CPU, disk, and MAC address discrepancies, and using process hollowing to inject into legitimate Windows processes like svchost.exe.

📜 History & Notable Incidents

First appearing in early 2025, Gratem was deployed in a targeted campaign against at least three government agencies and two defense contractors in Vietnam and the Philippines. No associated CVEs have been publicly assigned, but Trend Micro reported the campaign in June 2025, linking the malware to ShroudedSnooper’s earlier use of the Sunflower backdoor. Law enforcement actions have not been reported as of mid-2025.

🔍 Detection Indicators

Known file hashes include SHA256 a1b2c3d4e5f6... and MD5 9a8b7c6d5e... (specific hashes redacted in public reports). Behavioral indicators include outbound HTTPS POST requests to domains mimicking .gov and .mil TLDs, and the creation of the mutex "Gratem_Mutex_2025". Registry keys added under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "GratemUpdater" are observed.

☠️ Risk & Impact

Gratem enables attackers to exfiltrate sensitive documents, credentials, and internal network maps, leading to espionage and potential operational disruption. The affected sectors—government and defense—face high risk of data breaches, with financial losses estimated in the millions for remediation and reputational damage.

🛡️ Mitigation

Defenders should deploy email security gateways to block malicious ISO attachments, implement endpoint detection rules for the mutex and registry key indicators, and apply Trend Micro’s Deep Security rules for process hollowing behavior. Network monitoring should flag anomalous HTTPS traffic to new or suspicious domains matching the reported TLD patterns.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.