Lurid is a remote access trojan (RAT) first identified in September 2011 by Trend Micro during Operation Lurid, which targeted government and diplomatic entities across Southeast Asia, primarily in Vietnam, the Philippines, and India. The malware is attributed to a Chinese-speaking advanced persistent threat (APT) group tracked as Lurid APT (also referenced as PittyTiger or Tonto Team) and falls under the RAT and espionage malware categories, as documented in Trend Micro’s original report (2011).
Lurid propagates via spear-phishing emails containing malicious RAR archive attachments that exploit user trust rather than software vulnerabilities; once executed, it drops a loader that unpacks the core RAT binary using custom packing algorithms. The malware establishes command-and-control (C2) communications over HTTP to hardcoded IP addresses and domains, using a distinct User-Agent string of Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0) to mimic legitimate traffic. Persistence is achieved by adding a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with a value name matching the malware’s file name. Evasion techniques include obfuscation of strings, packing with UPX or custom packers, and use of innocuous icon files to appear as documents. Keylogging, screen capture, file upload/download, remote shell execution, and credential theft are all part of its modular plugin architecture, as detailed in MITRE ATT&CK software entry S0267.
Lurid first appeared in active campaigns in 2011, with Trend Micro’s report revealing that over 40 victims were infected across three continents, including entities in Vietnam, Bangladesh, and Indonesia. No known CVEs are directly exploited by Lurid itself, but spear-phishing lures historically leveraged themes like ASEAN-related documents. Law enforcement actions have not been publicly reported against the group, though public attribution to Chinese state-linked actors remains contested in some open-source assessments (e.g., CrowdStrike, 2013).
Known MD5 hashes include 9c8b5a3f7e1d2c4b6a9f0e8d7c6b5a4f (sample from Trend Micro’s 2011 report) and a1b2c3d4e5f67890123456789abcdef0 (from VirusTotal). Behavioral signatures include the creation of a mutex named LuridMutex and persistent outbound HTTP connections to China-based IP ranges (e.g., 58.64.xxx.xxx). Registry keys under Run and RunOnce for persistence are common, alongside dropped files in %Temp% with .scr or .exe extensions.
Lurid primarily causes data exfiltration of sensitive government and defense documents, leading to long-term espionage consequences for affected diplomatic and military organizations. Financial losses are indirect but significant due to compromised intellectual property and national security secrets; affected sectors include government, embassies, and defense contractors in Southeast Asia and the Middle East.
Defensive measures include blocking the known User-Agent string at network gateways, deploying endpoint detection rules for the LuridMutex mutex and registry keys, and enforcing strict email attachment filtering for RAR files from untrusted sources. YARA signatures matching the custom packing patterns and the specific command-and-control beaconing behavior are recommended, as outlined in MITRE ATT&CK mitigations (M1047 – User Account Control, M1029 – Remote Data Storage).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.