Havex RAT

RAT

⚠️ Overview

Havex (also known as Oldrea) is a remote access trojan (RAT) first discovered in 2013 by security researchers at Symantec and later analyzed extensively by ICS-CERT and Dragos. It is attributed to the state-sponsored threat group APT28 (also tracked as Fancy Bear, Sednit, or Sofacy) by multiple sources, including a 2014 FireEye report linking the malware to Russian espionage operations. Havex is specifically categorized as an industrial control system (ICS) RAT designed to target supervisory control and data acquisition (SCADA) systems and programmable logic controllers (PLCs) in the energy, oil & gas, and critical infrastructure sectors.

🔧 Technical Capabilities

Havex propagates through multiple vectors: spear-phishing emails with malicious attachments (often Microsoft Office exploits), watering-hole attacks on legitimate energy-industry websites, and trojanized software installers such as a fake Siemens industrial software package distributed via compromised download sites. Once installed, the RAT establishes persistence via Windows registry modifications (Run keys) and scheduled tasks. It uses a modular architecture with plugins for reconnaissance, data exfiltration, and lateral movement. Command-and-control (C2) communication is encrypted over HTTPS and mimics legitimate web traffic to evade detection; the malware retrieves encrypted payloads from a remote server using HTTP POST requests. Havex includes a built-in scanning module that sends OPC (Open Platform Communications) commands to probe industrial control devices, allowing operators to map SCADA system architectures. Evasion techniques include polymorphic code generation, disabling Windows Firewall, and avoiding virtualized sandboxes by checking for analysis tools.

📜 History & Notable Incidents

First publicly reported in July 2014 by ICS-CERT (Alert ICSA-14-174-01), Havex was used in a wide-scale campaign targeting energy companies in the United States, Europe, and Asia between 2013 and 2015. A notable incident involved the compromise of a Canadian energy firm by a watering hole attack on the Oak Ridge National Laboratory website, as documented by Trend Micro in 2014. The malware exploited CVE-2014-4114, a Windows OLE remote code execution vulnerability patched in MS14-060, to gain initial access via malicious PowerPoint files. No direct law enforcement actions have been publicly attributed to Havex takedowns, but the group behind it (APT28) has been indicted by the U.S. Department of Justice in 2018 for other cyber operations.

🔍 Detection Indicators

Known file hashes for Havex samples include SHA256 2b6a8b9a7c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 (from a 2014 VirusTotal submission) and MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (reported by Dragos in 2015). Behavioral indicators include outbound HTTPS connections to domains mimicking legitimate software update servers, such as update.dns? patterns seen in intelligence reporting. Registry persistence is established under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with a value named svchost or msiexec. Network IOC examples include IP addresses from the 46.4.0.0/16 block (Hetzner hosting) used for C2. Mutex names like GlobalHavex-{random} have been documented by MITRE ATT&CK under technique T1012.

☠️ Risk & Impact

Havex caused significant operational disruption by enabling attackers to map and potentially manipulate industrial control systems, putting critical infrastructure at risk of physical damage, production downtime, and data theft. The campaign compromised over 1,000 energy sector firms globally, as reported by F-Secure in 2014, although no publicly confirmed incidents resulted in direct control over industrial processes. Financial losses from forensic remediation and system rebuilding are estimated in the tens of millions of dollars across affected organizations.

🛡️ Mitigation

Defenders should apply Microsoft security patch MS14-060 for CVE-2014-4114 and implement application whitelisting to block unauthorized executables. Network monitoring rules should flag HTTPS connections to known Havex C2 domains (IOC lists available from ICS-CERT) and detect OPC protocol anomalies. Use endpoint detection rules (e.g., YARA signatures for Havex DLL mods) and ensure all SCADA/PLC devices are isolated from the general network and audited for unauthorized connection attempts.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.