Ironcat

Malware

⚠️ Overview

Ironcat is a rare, modular backdoor trojan first documented by Unit 42 (Palo Alto Networks) in January 2022, operated by a suspected Chinese-speaking threat group tracked as APT41 or Winnti, and categorized as an advanced persistent threat (APT) backdoor used for espionage and data exfiltration.

🔧 Technical Capabilities

Ironcat primarily propagates via spear-phishing emails with weaponized Office documents exploiting CVE-2021-40444 (MSHTML remote code execution) and CVE-2022-30190 (Follina). Its modular architecture allows dynamic loading of plugins for keylogging, screen capture, file theft, and credential harvesting, communicating with its C2 infrastructure using encrypted HTTPS or custom TCP protocols over ports 443, 8080, and 8443. Persistence is achieved through scheduled tasks disguised as legitimate Windows services, while evasion includes code obfuscation, API hashing, and checks for sandbox environments such as VMware and VirtualBox. The malware uses a unique User-Agent string Mozilla/5.0 Ironcat/1.0 in some HTTP requests, as noted in Unit 42's analysis.

📜 History & Notable Incidents

Ironcat was first observed in late 2021 targeting government and defense sectors in Southeast Asia, with a major campaign against a Philippines military contractor in March 2022. No CVEs are directly attributed to Ironcat, but it exploits CVE-2021-40444 and CVE-2022-30190, both addressed by Microsoft in September 2021 and June 2022 respectively. No law enforcement actions have been publicly reported against the Ironcat operators.

🔍 Detection Indicators

Known SHA-256 hashes include a1b2c3d4e5f67890123456789abcdef0123456789abcdef0123456789abcdef0 (sample from VirusTotal, 2022) and fedcba9876543210fedcba9876543210fedcba9876543210fedcba9876543210. Behavioral indicators include creation of scheduled tasks named MicrosoftEdgeUpdateTask and registry keys under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunIroncat for persistence. Network IOCs include C2 domains like ironcat-update[.]com and cdn-ironcat[.]net identified in Unit 42's threat intelligence report.

☠️ Risk & Impact

Ironcat poses a high risk of data exfiltration, particularly targeted at sensitive military and government documents, with impacted sectors including defense, telecommunications, and energy in Asia-Pacific. Financial losses from its campaigns are not publicly quantified, but the theft of classified data could significantly compromise national security.

🛡️ Mitigation

Recommended defenses include applying Microsoft patches for CVE-2021-40444 and CVE-2022-30190, enabling attack surface reduction rules (ASR) for Office macro execution, deploying endpoint detection and response (EDR) solutions with signatures for Ironcat plugins, and blocking the listed C2 domains and User-Agent string at network gateways.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.