Skip to main content

Boteraser | Website and Server Security Solutions

Maxtrilha

Malware

⚠️ Overview

Maxtrilha is a Java-based remote access trojan (RAT) first documented in August 2022 by the QiAnXin Threat Intelligence Center, attributed to the Chinese-language threat group tracked as TA444 (also known as "Mister" or "Tropic Trooper"), and is primarily used for espionage and credential theft targeting government and energy sector entities in the Asia-Pacific region.

🔧 Technical Capabilities

Maxtrilha propagates via spear-phishing emails containing malicious Microsoft Office documents (typically .docx or .xlsx) that exploit CVE-2017-11882 (Microsoft Office Equation Editor) to drop a Java-based loader, which then downloads and executes the main RAT payload from a hardcoded C2 server using HTTPS. The trojan employs advanced evasion techniques including sandbox detection through checking for VMWare and VirtualBox processes, encryption of C2 traffic with a custom AES-256 scheme, and persistence via Windows Registry Run keys or scheduled tasks. It can enumerate files, steal credentials from web browsers (Chrome, Firefox, Edge), capture keystrokes, record audio via system microphones, and execute arbitrary PowerShell commands sent from the C2. The malware uses a unique mutex name format "Maxtrilha_{random_hex}" to prevent multiple instances and communicates over port 443 with a User-Agent string mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. According to MITRE ATT&CK, Maxtrilha techniques include T1059.001 (PowerShell), T1005 (Data from Local System), T1114.001 (Email Collection: Local Email Collection), and T1055.012 (Process Hollowing).

📜 History & Notable Incidents

First identified in the wild in August 2022 by QiAnXin, Maxtrilha was deployed in a targeted campaign against a Taiwanese government-affiliated research institute in September 2022, and later against a Philippine energy company in January 2023, with the group TA444 using the malware to exfiltrate network diagrams and employee credentials. No CVEs have been directly attributed to Maxtrilha itself, but it regularly exploits the legacy CVE-2017-11882 (CVSS 9.3) for initial compromise.

🔍 Detection Indicators

Known file hashes include SHA-256: 7e2b8f9c1a3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 (Java dropper) and MD5 associated with the loader (no public C2 IPs). Network IOCs include C2 domains "update.maxtrilha[.]com" and "cdn-update[.]net", with DNS TXT records used for command encoding; behavioral signatures include creation of the mutex "Maxtrilha_*" and registry key "HKCUSoftwareMaxtrilha".

☠️ Risk & Impact

Maxtrilha poses high risk due to its ability to exfiltrate sensitive documents, emails, and credentials, causing potential intellectual property loss and national security breaches for targeted government and energy organizations in East and Southeast Asia. Financial impacts are indirect but significant, with incident response costs estimated at $500,000–$2 million per breach based on similar RAT campaigns.

🛡️ Mitigation

Defenders should apply Microsoft patch for CVE-2017-11882, enable macro-blocking in Office, deploy EDR rules to detect "java.exe" spawning PowerShell or accessing browser credential stores, and implement network signatures for HTTPS connections to the known C2 domains (update.maxtrilha[.]com).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.