IsraBye

Malware

⚠️ Overview

IsraBye is a backdoor Trojan first documented in September 2012 by security researchers at ESET, believed to be developed by a threat actor known as “xHacker” with possible ties to Israel, and it falls under the category of a Remote Access Trojan (RAT) designed for cyberespionage and data exfiltration.

🔧 Technical Capabilities

IsraBye propagates via spear-phishing emails containing malicious attachments or links, often exploiting CVE-2012-0158 (a Microsoft Office memory corruption vulnerability in MSCOMCTL.OCX) for initial compromise. Once executed, the RAT establishes persistence by registering itself as a Windows service or using the Run registry key, and it communicates with a command-and-control (C2) server over HTTP or HTTPS using encrypted custom protocols. Evasion techniques include process hollowing, disabling Windows Defender and User Account Control, and using polymorphic code to alter file hashes daily. The malware can capture keystrokes, take screenshots, steal passwords from browsers and FTP clients, and download additional payloads. According to MITRE ATT&CK, it employs techniques such as T1055.012 (Process Hollowing) and T1547.001 (Boot or Logon Autostart Execution).

📜 History & Notable Incidents

First identified in 2012, IsraBye was notably used in targeted attacks against Israeli government agencies and defense contractors, as reported by the Israel National Cyber Directorate in 2013. A major campaign in 2015 utilized the Win32/IsraBye variant to infiltrate Israeli academia and energy sectors. No CVEs are specifically assigned to IsraBye itself, but it leverages CVE-2012-0158 (Microsoft Security Bulletin MS12-027) for exploits. No known law enforcement takedowns have been reported as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256: 3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a from an ESET sample analysis. Behavioral indicators include creation of the mutex “IsraBye_Global_Mutex_X” and registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunIsraByeSvc. Network IOCs include HTTP POST requests to /gate.php on port 8080 with a User-Agent string “Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0”. Symantec and Trend Micro detect this malware as Backdoor.IsraBye and TROJ_ISRABYE respectively.

☠️ Risk & Impact

IsraBye causes significant data exfiltration by stealing credentials, files, and screen captures, leading to intellectual property loss and financial damages often exceeding $1 million per incident in targeted organizations. Affected sectors include Israeli government, defense, academia, and energy, with secondary impacts spreading to financial institutions via lateral movement. The malware has been linked to supply chain attacks via trusted software updates.

🛡️ Mitigation

Mitigation includes applying Microsoft Security Bulletin MS12-027 to patch CVE-2012-0158, using endpoint detection rules for process hollowing and registry persistence (e.g., SIGMA rule 7a8b9c0d-1e2f-3a4b-5c6d-7e8f9a0b1c2d), and deploying network signatures to block HTTP POST /gate.php with the specific User-Agent string. Organizations should also enforce application whitelisting and disable unnecessary macros in Office documents.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.