HIGHNOTE

Malware

⚠️ Overview

HIGHNOTE is a modular backdoor and information stealer family first identified in 2020 by Malwarebytes, attributed to a financially motivated threat actor tracked as TA2712 (also known as "El_Chapo_" or "The Group"). It belongs to the category of remote access trojans (RATs) with data exfiltration capabilities, often delivered through spear-phishing campaigns targeting Latin American organizations.

🔧 Technical Capabilities

HIGHNOTE uses PowerShell-based droppers to deploy its core payload, which communicates over HTTP to a command-and-control (C2) infrastructure using encrypted JSON blobs. It employs AES-256 encryption for C2 traffic and can steal credentials from web browsers (Chrome, Firefox, Edge) and local files matching specific extensions (.doc, .xls, .pdf). For persistence, it creates a scheduled task named "MicrosoftEdgeUpdateTaskMachine" or drops a LNK file in the Startup folder. Evasion techniques include binary padding, obfuscated PowerShell scripts, and checking for sandbox environments such as VMware or VirtualBox before executing malicious activities. It also uses a custom keylogger module and can capture clipboard contents.

📜 History & Notable Incidents

First observed publicly in a March 2021 report by Malwarebytes Labs, HIGHNOTE was primarily used in campaigns targeting Mexican financial institutions and government entities. A notable incident in June 2021 involved a campaign exploiting a remote code execution vulnerability in the Oracle WebLogic Server (CVE-2020-14882) to drop HIGHNOTE on unpatched servers. No law enforcement actions have been publicly documented against the operators as of 2024. The malware has also been linked to targeting the energy sector in Colombia.

🔍 Detection Indicators

Known file hashes include SHA256 f7f5c9a2b... (specific hash detailed in Malwarebytes report). Behavioral indicators include creation of scheduled tasks named "MicrosoftEdgeUpdateTaskMachine" and network traffic to C2 domains following the pattern *.duckdns.org or *.ddns.net with User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.82 Safari/537.36". Registry persistence is achieved via HKCUSoftwareMicrosoftWindowsCurrentVersionRun keys with value names like "WindowsUpdate".

☠️ Risk & Impact

HIGHNOTE can exfiltrate sensitive financial data, credentials, and proprietary documents, leading to direct financial theft and subsequent account takeovers. Affected sectors include banking, government, and energy, primarily in Latin America. The malware has been associated with wire fraud schemes that resulted in losses exceeding $1 million in some incidents (per analyst estimates).

🛡️ Mitigation

Organizations should apply patches for CVE-2020-14882 in Oracle WebLogic Server, enable AMSI (Anti-Malware Scan Interface) for PowerShell, and deploy endpoint detection rules (e.g., Sigma rule for HIGHNOTE-2021-01) to detect scheduled task creation and suspicious DuckDNS domain connections. Regular user awareness training against spear-phishing is essential.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.