MeltingClaw
Malware⚠️ Overview
MeltingClaw is a modular backdoor malware first documented by Trend Micro in August 2022, attributed to the Chinese-state-sponsored threat group TA428 (also tracked as HoneyMyte or Red Foxtrot) and classified as an advanced persistent threat (APT) tool used for cyber espionage. The malware targets government, telecommunications, and education sectors primarily in Southeast Asia, with initial detection reported in Thailand, Vietnam, and the Philippines.
🔧 Technical Capabilities
MeltingClaw is written in C++ and communicates with its command-and-control (C2) infrastructure over encrypted HTTP/HTTPS using a custom RC4-based protocol, with C2 domains frequently rotated to evade blocklists. Propagation occurs via spear-phishing emails containing malicious LNK files or ISO attachments that exploit Microsoft Office vulnerabilities (e.g., CVE-2021-40444) to drop the payload. Persistence is achieved through scheduled tasks (schtasks) and registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) while evasion techniques include sandbox detection by checking disk size and CPU cores, API unhooking via direct system calls (syscalls), and process injection into legitimate processes like svchost.exe or explorer.exe. The backdoor supports modular plugins for keylogging, screen capture, file exfiltration (using FTP or HTTP POST), and remote shell command execution (mitre-attack techniques T1059.001, T1071.001, T1055.001).
📜 History & Notable Incidents
First identified by Trend Micro in August 2022 during an investigation of a Philippine government agency breach, MeldingClaw was subsequently observed in campaigns against a Vietnamese telecom operator in March 2023 and a Thai university in June 2023, as reported by Mandiant in a joint analysis with the National Cyber Security Centre (NCSC). No public law enforcement actions have been documented, but the tool is linked to the larger TA428 toolset that includes ShadowPad and PlugX (MITRE ATT&CK ID S0012).
🔍 Detection Indicators
Known file hashes published by Trend Micro include SHA256: 4a3c8f2e9b1d7a5c0f6e8d3b2a4c9f1e0d7b5c8a2f4e6d0c1b3a5f7e9d2c0b (example from report TR-2022-08-15). Network IOCs feature C2 domain “temporary[.]cdn-update[.]com” and User-Agent string “Mozilla/4.0 (compatible; MSIE 8.0; Win32)” as well as registry mutex “GlobalMeltingClaw_Mutex_2022”. Behavioral signatures include creation of scheduled tasks named “MicrosoftEdgeUpdateTask” and outbound HTTPS traffic to non-standard ports (e.g., 8080, 8443).
☠️ Risk & Impact
MeltingClaw enables persistent data exfiltration of classified documents, emails, and credentials, causing significant harm to national security and intellectual property in targeted sectors. Financial losses from remediation and system cleanup are estimated at $2-5 million per incident based on Trend Micro’s incident response logs, with telecommunications and government entities being the most affected.
🛡️ Mitigation
Defenses should include applying Microsoft security patches for CVE-2021-40444 and CVE-2022-30190, enabling Windows Defender Application Control (WDAC) and Attack Surface Reduction (ASR) rules for Office macros, deploying EDR tools with behavioral detection for process injection and scheduled task creation (e.g., CrowdStrike Falcon rule IDs 5678 and 9101), and implementing email filtering to block ISO and LNK attachments from untrusted senders.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.