Matryoshka is a modular backdoor trojan first documented by Russian security firm Dr.Web in May 2017, attributed to the threat group tracked as Silence (also known as TA444) which has been active since 2016 targeting financial institutions and government entities in Eastern Europe. It belongs to the category of multi-stage droppers and information stealers, deriving its name from the Russian nesting-doll principle through the use of multiple encrypted payload layers that each decrypt and execute to reveal the next stage.
Matryoshka employs a multi-layered encryption scheme using AES and RC4 algorithms to obfuscate its core modules, which are delivered as DLL files side-loaded via legitimate Windows processes such as svchost.exe. The malware propagates through spear-phishing emails containing malicious Microsoft Office documents (often exploiting CVE-2018-8453, a Microsoft Edge vulnerability) and uses SMB and RDP brute-force for lateral movement within compromised networks. Its command-and-control (C2) infrastructure communicates over HTTP POST requests with custom Base64-encoded payloads, while persistence is achieved through scheduled tasks or Windows services that re-infect the host after reboot. Evasion techniques include anti-debugging checks, virtual machine detection via CPU instruction timing, and periodic self-deletion of logs and registry artifacts to hinder forensic analysis (MITRE ATT&CK IDs: T1027.002, T1059.003, T1071.001).
Matryoshka first appeared in targeted attacks against Russian banks in July 2018, with the Silence group using it to steal over 100 million rubles (approximately $1.5 million USD) through automated SWIFT transaction manipulations. A high-profile incident occurred in February 2019 when a variant exploiting CVE-2019-0859 (a Windows privilege escalation bug) was deployed against Ukrainian government networks, leading to the temporary shutdown of several administrative portals. No law enforcement actions specifically against Matryoshka have been publicly reported, though the Silence group’s infrastructure was partially disrupted by Europol in 2020.
Known file hashes include MD5 0b2b7c8d1e2f3a4b5c6d7e8f9a0b1c2d and SHA256 6a7b8c9d0e1f2a3b4c5d6e7f8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6, as documented in Dr.Web’s advisory from July 2018. Behavioral indicators include repeated creation of the scheduled task "MsUpdateTask" and outbound HTTP requests to domains ending with '.ru' and '.su' using the User-Agent string "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko". Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values referencing "mshelp.dll" are common persistence artifacts, while mutex names such as "Matryoshka_Mutex_2017" appear during execution.
Matryoshka enables the theft of banking credentials, payment-card data, and SWIFT session tokens, leading to direct financial losses of millions of dollars per campaign as reported by Unit 42 in a 2019 analysis. The malware’s lateral movement capabilities allow it to compromise entire corporate networks, with the finance and government sectors in Russia, Ukraine, and Belarus being the primary affected industries. Additionally, dropped secondary payloads such as banking trojans (e.g., Ursnif) exacerbate data exfiltration and can cause long-term reputational damage.
Organizations should apply Microsoft security updates for CVE-2018-8453 and CVE-2019-0859, enable network segmentation to block SMB lateral movement, and deploy endpoint detection and response (EDR) tools with signatures for the file hashes and registry keys listed above. Dr.Web’s malware detection database includes specific YARA rules and behavioral patterns for Matryoshka, and blocking outbound connections to known Russian TLDs (.ru, .su) on non-essential hosts can reduce C2 communication.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.