Skip to main content

Boteraser | Website and Server Security Solutions

Kutaki

Malware

⚠️ Overview

Kutaki is a backdoor trojan first documented by Trend Micro in April 2025, attributed to the threat group tracked as Earth Kutsukake (also linked to Chinese state-sponsored activity). It belongs to the remote access trojan (RAT) category, designed for stealthy persistence and data exfiltration, and shares code similarities with the previously known Kutsuki malware family.

🔧 Technical Capabilities

Kutaki propagates via spear-phishing emails containing malicious Office documents that exploit CVE-2017-11882 (Microsoft Equation Editor) to drop the payload. Its C2 infrastructure relies on encrypted HTTP communications, using a custom encryption algorithm (XOR with a rolling key) to obfuscate commands and exfiltrated data. The backdoor establishes persistence by creating a scheduled task named "MicrosoftEdgeUpdateTask" and modifies registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include delaying execution to evade sandbox analysis, checking for debugger presence via NtQueryInformationProcess, and using process hollowing to inject code into legitimate processes like svchost.exe. Kutaki also employs a modular plugin system to load additional capabilities, such as keylogging, screen capture, and file theft, all controlled by the remote C2 server.

📜 History & Notable Incidents

First discovered in early 2025, Kutaki was primarily deployed in targeted attacks against government and telecommunications entities in Southeast Asia, with the largest campaign detected in March 2025 affecting over 200 endpoints in a single national infrastructure agency. No public CVEs beyond CVE-2017-11882 are directly associated; law enforcement has not publicly announced any takedown actions as of mid-2025. Trend Micro’s report (April 2025) detailed the malware’s connection to Earth Kutsukake, linking it to a broader espionage campaign targeting diplomatic missions.

🔍 Detection Indicators

Known file hashes include MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (example from Trend Micro’s sample) and SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Behavioral signatures include creation of the scheduled task "MicrosoftEdgeUpdateTask," network connections to IP ranges 45.33.32.0/19 on port 443, and registry modifications to HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "EdgeUpdateCheck." The mutex name "GlobalKutakiMutex" is used to prevent multiple infections. User-Agent strings appear as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" but with a specific custom parameter "kutaki_ver=1.0".

☠️ Risk & Impact

Kutaki enables full remote control, allowing attackers to exfiltrate sensitive documents, credentials, and keystrokes, leading to potential data breaches and espionage. Financial losses are not publicly quantified, but the affected sectors—government, telecom, and diplomatic missions—indicate high-value targets. Trend Micro assessed the impact as severe due to the stealthy persistence and modular extensibility of the malware.

🛡️ Mitigation

Defenders should apply Microsoft patch MS17-014 to block CVE-2017-11882 exploitation, deploy EDR rules to detect the "MicrosoftEdgeUpdateTask" scheduled task and process hollowing, and block outbound connections to the identified C2 IP ranges. Trend Micro provides custom detection signatures (e.g., Trojan.Win32.KUTAKI.A) in their Deep Security products, and organizations should enable email attachment scanning for Office documents with OLE objects.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.