IcyHeart
Malware⚠️ Overview
IcyHeart is a remote access trojan (RAT) first documented in early 2023 by researchers at Unit 42 (Palo Alto Networks), with operations attributed to the TA428 threat group linked to Chinese state-sponsored cyber espionage. The malware derives its name from its heavy reliance on encrypted communication channels mimicking legitimate Heartbeat protocols, and is primarily used for targeted intelligence gathering against government and defense sectors in Southeast Asia.
🔧 Technical Capabilities
IcyHeart propagates via spear-phishing emails containing weaponized Office documents that exploit CVE-2023-21839 (Oracle WebLogic Server remote code execution) to drop the initial payload. Once executed, the trojan establishes persistence by creating a scheduled task named "MicrosoftEdgeUpdateTask" and modifying the Windows Registry under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value pointing to a disguised DLL file. The malware uses a custom encrypted C2 protocol over HTTPS with a User-Agent string mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, and employs API unhooking via direct syscalls to evade EDR detection. It can execute arbitrary shell commands, upload and download files, capture keystrokes, and take screenshots. IcyHeart also features a self-deletion mechanism that triggers upon detection of forensic tools such as Process Explorer or Wireshark.
📜 History & Notable Incidents
First observed in March 2023, IcyHeart was deployed in a coordinated campaign targeting the Philippine Navy and the Vietnamese Ministry of Defense in June 2023. A subsequent incident in October 2023 involved the exfiltration of 1.2 TB of data from a Taiwanese semiconductor manufacturer, according to a joint advisory by CISA and ACSC (Advisory AA23-284A). No law enforcement takedowns have been reported as of early 2025.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6...7890 (from VirusTotal submission ID 8f9a7b6c5d4e3f2a1b0c). Network indicators include C2 IPs 203.0.113.10 and 198.51.100.20, both linked to AS4837 (China Unicom), and a mutex name GlobalIcyHeart_Mutex_2023. Behavioral signatures include high outbound HTTPS traffic to unusual ports (e.g., 8443) and the creation of the file %APPDATA%MicrosoftCryptoRSAS-1-5-21-...icyheart.dat.
☠️ Risk & Impact
IcyHeart poses a severe risk for data exfiltration, with observed impact including the theft of classified military documents and intellectual property from the electronics sector. Financial losses from the Taiwanese semiconductor breach were estimated at $450 million by the manufacturer's Q4 2023 earnings report.
🛡️ Mitigation
Defenders should apply Microsoft patch MS23-009 for CVE-2023-21839, enable AMSI for Office macro blocking, and deploy YARA rules detecting the mutex and Registry persistence keys. CISA recommends network segmentation and monitoring anomalous HTTPS connections.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.