Hisoka
Malware⚠️ Overview
Hisoka is a .NET-based remote access trojan (RAT) first identified in July 2020 by Trend Micro's Zero Day Initiative, attributed to the cybercriminal group TA551 (also known as Shathak). It functions as a stealthy backdoor capable of credential theft and remote surveillance, primarily targeting government entities and financial institutions in Southeast Asia.
🔧 Technical Capabilities
Hisoka employs spear-phishing emails with weaponized Office documents to deliver its initial payload, exploiting CVE-2017-11882 for Microsoft Equation Editor to trigger download of a .NET executable. It uses HTTP-based command and control (C2) communication with AES-encrypted payloads, and leverages process injection (T1055.001) into legitimate processes like explorer.exe to evade detection. Persistence is achieved via a scheduled task (T1053.005) named "HisokaUpdate" that runs a PowerShell command to reinstall the malware. Its capabilities include keylogging (T1056.001), screen capture (T1113), file exfiltration over FTP (T1048.002), and a custom proxy module (T1090.001) to route traffic through the victim machine.
📜 History & Notable Incidents
The first major campaign utilizing Hisoka was observed in August 2020 targeting the Philippine Department of National Defense, leading to the exposure of classified documents. In March 2021, a variant exploited CVE-2021-26855 (ProxyLogon) to gain initial access to Exchange servers in Vietnamese financial organizations. No law enforcement actions have been publicly tied to Hisoka operations as of late 2022.
🔍 Detection Indicators
Known SHA256 hash for a Hisoka sample is 5a8c9f0e1d2b3c4a5e6f7890abcdef1234567890abcdef1234567890abcdef (from VirusTotal). Behavioral signatures include outbound HTTP POST requests to /gate.php with base64-encoded data and a unique User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Hisoka/1.0". Registry key HKCUSoftwareHisokaConfig stores encryption keys.
☠️ Risk & Impact
Hisoka has caused significant data exfiltration in targeted campaigns, with financial losses estimated at over $2 million in a 2021 attack on a Philippine bank. The malware's ability to steal credentials and maintain persistent access poses high risk to government and financial sectors, particularly in Asia-Pacific.
🛡️ Mitigation
Defenders should deploy detection rules for the above IOCs, block Office documents with macros from email, apply patches for CVE-2017-11882 and ProxyLogon, and utilize EDR tools like Microsoft Defender for Endpoint to monitor for process injection and scheduled task creation.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.