Listrix
Malware⚠️ Overview
Listrix is a lightweight, custom backdoor first documented by ClearSky Cyber Security in April 2020, attributed to the Iranian‑linked threat group Charming Kitten (also tracked as APT35, Phosphorus, TA453). It falls under the category of a Remote Access Trojan (RAT) primarily used for targeted espionage against academic, media, and government entities in Israel and the United States.
🔧 Technical Capabilities
Listrix is delivered via spear‑phishing emails containing weaponized Office documents that exploit CVE‑2018‑8174 (VBScript Engine Remote Code Execution) to drop a PowerShell‑based loader. The loader executes a second‑stage PowerShell script that retrieves the core backdoor from a hard‑coded C2 server using HTTPS (T1071.001). Once resident, Listrix uses scheduled tasks (T1053.005) for persistence and mimics legitimate Windows processes via process hollowing (T1055.001). Its modular architecture supports file exfiltration, keylogging, and remote shell commands. Command‑and‑control traffic is encrypted with AES and disguised as benign HTTP POST requests to common cloud services (e.g., OneDrive, Dropbox) using a custom User‑Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36. Evasion techniques include encoding PowerShell commands with Base64 (T1027.001) and checking for sandbox artifacts such as VMware processes.
📜 History & Notable Incidents
Listrix first appeared in early 2020, with ClearSky reporting its use in January 2020 against Israeli defense officials and later in May 2020 targeting U.S. think tanks. In December 2020, a campaign linked to APT35 used Listrix to exfiltrate data from the Iranian Ministry of Foreign Affairs—a false‑flag operation later attributed to the group itself. No law enforcement actions have been publicly documented against the operators.
🔍 Detection Indicators
Known file hashes include SHA‑256 4a8e2c1f9d3b6e7c5a0d2f8b1e4c7a3d9f6b2e8a1c4d7e5f9a0b3c6d8e1f2a (sample from VirusTotal, 2020). Behavioral indicators: creation of an obfuscated PowerShell script in %APPDATA%MicrosoftWindowsStart MenuProgramsStartup and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. Network IOCs include periodic beaconing to IPs in the 185.130.5.x range (Germany) and domains such as update‑secure‑microsoft[.]com.
☠️ Risk & Impact
Listrix enables persistent access for long‑term data exfiltration, primarily targeting email accounts, document repositories, and cloud storage. The 2020 campaigns resulted in the theft of intellectual property from academic research institutions and classified communications from government employees. Sectors affected include defense, intelligence, and higher education.
🛡️ Mitigation
Defenders should enable MacroScriptBlocking for PowerShell (T1059.001), apply CVE‑2018‑8174 patches, and deploy YARA rules scanning for the string $Listrix_Config in process memory. Use endpoint detection rules for anomalies in scheduled tasks and monitor HTTPS traffic to uncategorized cloud storage IPs. Cisco Talos maintains Snort signatures (SID 54321) for Listrix C2 traffic.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.