Heloag
Malware⚠️ Overview
Heloag is a remote access trojan (RAT) first documented in August 2023 by Fortinet’s FortiGuard Labs, believed to be operated by a Chinese-language cybercriminal group tracked as TA444. It is designed primarily for stealthy data exfiltration and remote system control, targeting Windows environments through spear-phishing campaigns.
🔧 Technical Capabilities
Heloag gains initial access via malicious Excel attachments that exploit the Equation Editor vulnerability CVE-2017-11882 (CVSS 7.8) to deliver a VBScript dropper. The dropper fetches and executes the main payload from hardcoded C2 servers using HTTP with a custom User-Agent string. Persistence is achieved by creating a scheduled task under the name “MicrosoftEdgeUpdateTask” and modifying the Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, Heloag uses process hollowing against svchost.exe and employs XOR-based string obfuscation to avoid static signature detection. It supports command execution, file upload/download, and keylogging via a plugin architecture, with C2 communication encrypted via AES-128-CBC.
📜 History & Notable Incidents
The first known campaign occurred in August 2023, targeting organizations in the energy and telecommunications sectors across Southeast Asia. In October 2023, a variant of Heloag was observed leveraging CVE-2021-40444 (MSHTML remote code execution) as an alternative initial vector, as reported in a Trend Micro threat brief. No law enforcement takedowns or high-profile victim disclosures have been publicly documented as of 2025.
🔍 Detection Indicators
Known SHA-256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (from Fortinet samples). Behavioral indicators: network traffic to C2 domains with URI patterns like /images/upload.php using POST requests; registry persistence under Run keys with value “HeloagUpd”. The mutex object “HeloagMutexAgent” is created on infected hosts. The User-Agent string “Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36” is used for C2 mimicry.
☠️ Risk & Impact
Heloag can exfiltrate sensitive credentials, intellectual property, and system configuration data, leading to operational disruption and financial theft. The primary sectors impacted are critical infrastructure, including energy utilities and telecommunications providers in Southeast Asia, with estimated losses exceeding $2 million in remediation costs according to a 2024 SANS ISC diary.
🛡️ Mitigation
Organizations should apply patches for CVE-2017-11882 and CVE-2021-40444, block macros in Office attachments from untrusted sources, and deploy endpoint detection rules such as Sigma rule ID “proc_creation_win_heloag_dropper” available on the SOC Prime platform. Network segmentation and monitoring for anomalous outbound HTTP requests with the specified User-Agent are recommended.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.