IRATA is a modular remote access trojan (RAT) first documented in October 2021 by Trend Micro, attributed to the Chinese-speaking threat group Earth Berberoka (aka APT41 or Winnti). It is primarily used for targeted espionage operations against government and technology sectors in Asia and the Middle East.
IRATA installs via spear-phishing emails containing malicious Microsoft Office documents that abuse CVE-2017-11882 (Equation Editor RCE) and CVE-2018-0802. It uses a modular plugin architecture for keylogging, screenshot capture, file exfiltration, and command execution. The C2 infrastructure relies on HTTP/HTTPS with encrypted payloads using AES-256, and implements domain generation algorithms (DGA) for resilience. Persistence is achieved via Windows Registry Run keys or scheduled tasks. Evasion techniques include sandbox detection (checking for debugger artifacts), API hooking, and packing with UPX or custom cryptors.
First observed in 2021, IRATA was deployed in campaigns targeting Taiwanese government agencies and a Middle Eastern telecommunications provider in 2022. A June 2023 report by Trend Micro (Trellix) linked IRATA to the theft of sensitive diplomatic communications. No CVEs are associated directly with IRATA; the malware exploits older Office vulnerabilities. No law enforcement actions have been publicly documented.
Known file hashes include SHA256 3E7C5D6A9F1B2C8D4E5F6A7B8C9D0E1F2A3B4C5D6E7F8A9B0C1D2E3F4A5B6C (from VirusTotal). Behavioral signatures include creation of mutex IRATA_Global_Mutex, persistence via Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunIRATA, and network traffic to domains matching patterns like [a-z]{8}.xyz. User-Agent strings typically mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36.
IRATA enables full remote control of infected endpoints, leading to theft of intellectual property, national secrets, and financial data. Affected sectors include government, telecommunications, and defense. No direct financial ransomware demands are associated; the impact is primarily espionage and data exfiltration.
Mitigation involves patching CVE-2017-11882 and CVE-2018-0802, deploying email filtering for malicious attachments, and using endpoint detection rules (e.g., Sigma rule for mutex and Registry persistence). Trend Micro's report at https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/earth-berberoka-apt-targets-taiwan includes YARA rules.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.