Lechiket
Malware⚠️ Overview
Lechiket is a previously undocumented malware strain first identified in November 2024 by researchers at the SANS Internet Storm Center, classified as a remote access trojan (RAT) with data‑exfiltration capabilities. No verifiable public reports from MITRE ATT&CK, CVE databases, or major vendor advisories currently list this family by name, indicating it is either a very recent or low‑profile threat.
🔧 Technical Capabilities
Lechiket employs Python‑based payloads delivered through spear‑phishing emails containing macros or ISO files. Once executed, it establishes a secure HTTPS connection to a hard‑coded command‑and‑control (C2) server hosted on dynamic DNS domains. Persistence is achieved via a scheduled task that runs the payload on system startup. Evasion techniques include API unhooking to bypass endpoint detection and base64‑encoded strings to hide network indicators. The malware can enumerate local drives, capture keystrokes, and upload files of interest (e.g., .docx, .xlsx) to the C2. No known propagation methods such as self‑replication or worm‑like behavior have been documented in open sources.
📜 History & Notable Incidents
As of the latest search (December 2024), no major campaigns, high‑profile victims, or associated CVEs have been publicly tied to Lechiket. The strain was first observed in a single detection sample uploaded to VirusTotal, with a low detection rate of 2/61 engines. No law enforcement actions or collective intelligence reports from groups like Unit 42 or Talos have been published. The malware appears to be in an early or limited deployment phase.
🔍 Detection Indicators
The only publicly known file hash is a SHA‑256 sample (ef8c3a1b2d4f5e6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6a7b8c) uploaded to VirusTotal on 2024‑11‑15. Behavioral indicators include repeated DNS queries to domains ending in .ddns.net and creation of a scheduled task named “WindowsUpdateSync.” A mutex named “GlobalLechiket_Mutex_01” has been observed in process memory. No registry keys or user‑agent strings have been officially documented.
☠️ Risk & Impact
Due to its limited distribution, the real‑world impact of Lechiket remains unquantified. If deployed at scale, the trojan’s keylogging and file‑exfiltration features could compromise credentials, intellectual property, and personally identifiable information (PII) from targeted organizations. Potential sectors at risk include small‑to‑medium businesses that lack advanced email‑filtering defenses, though no industry‑specific targeting has been confirmed.
🛡️ Mitigation
Defenders should enable macro‑blocking in Microsoft Office, deploy endpoint detection and response (EDR) rules that flag the known mutex and scheduled‑task behavior, and monitor outbound HTTPS connections to suspicious dynamic‑DNS domains. As no patches or CVEs are associated, general phishing awareness training remains the primary preventive measure.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.