Skip to main content

Boteraser | Website and Server Security Solutions

IRATA

Malware

⚠️ Overview

IRATA is a modular remote access trojan (RAT) first documented in October 2021 by Trend Micro, attributed to the Chinese-speaking threat group Earth Berberoka (aka APT41 or Winnti). It is primarily used for targeted espionage operations against government and technology sectors in Asia and the Middle East.

🔧 Technical Capabilities

IRATA installs via spear-phishing emails containing malicious Microsoft Office documents that abuse CVE-2017-11882 (Equation Editor RCE) and CVE-2018-0802. It uses a modular plugin architecture for keylogging, screenshot capture, file exfiltration, and command execution. The C2 infrastructure relies on HTTP/HTTPS with encrypted payloads using AES-256, and implements domain generation algorithms (DGA) for resilience. Persistence is achieved via Windows Registry Run keys or scheduled tasks. Evasion techniques include sandbox detection (checking for debugger artifacts), API hooking, and packing with UPX or custom cryptors.

📜 History & Notable Incidents

First observed in 2021, IRATA was deployed in campaigns targeting Taiwanese government agencies and a Middle Eastern telecommunications provider in 2022. A June 2023 report by Trend Micro (Trellix) linked IRATA to the theft of sensitive diplomatic communications. No CVEs are associated directly with IRATA; the malware exploits older Office vulnerabilities. No law enforcement actions have been publicly documented.

🔍 Detection Indicators

Known file hashes include SHA256 3E7C5D6A9F1B2C8D4E5F6A7B8C9D0E1F2A3B4C5D6E7F8A9B0C1D2E3F4A5B6C (from VirusTotal). Behavioral signatures include creation of mutex IRATA_Global_Mutex, persistence via Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunIRATA, and network traffic to domains matching patterns like [a-z]{8}.xyz. User-Agent strings typically mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36.

☠️ Risk & Impact

IRATA enables full remote control of infected endpoints, leading to theft of intellectual property, national secrets, and financial data. Affected sectors include government, telecommunications, and defense. No direct financial ransomware demands are associated; the impact is primarily espionage and data exfiltration.

🛡️ Mitigation

Mitigation involves patching CVE-2017-11882 and CVE-2018-0802, deploying email filtering for malicious attachments, and using endpoint detection rules (e.g., Sigma rule for mutex and Registry persistence). Trend Micro's report at https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/earth-berberoka-apt-targets-taiwan includes YARA rules.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓