Micrass

Malware

⚠️ Overview

Micrass is a remote access trojan (RAT) first documented in public threat intelligence by Check Point Research in September 2019, attributed to advanced persistent threat (APT) groups operating from South Asia, specifically linked to the Donot Team (APT-C-35). It is categorized as a stealer and surveillance tool designed primarily for espionage against government and military entities in South and Southeast Asia.

🔧 Technical Capabilities

Micrass propagates via spear-phishing emails carrying malicious Microsoft Office documents (typically .doc or .xls) that exploit CVE-2017-0199 (a Microsoft Office OLE object vulnerability) to drop the payload. The malware uses a custom command-and-control (C2) protocol over HTTP/HTTPS, communicating with hardcoded IP addresses and domains; it periodically sends beacon requests with base64-encoded system information. Persistence is achieved through Windows Registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun), and it employs process hollowing to evade detection by injecting into legitimate processes like svchost.exe or explorer.exe. Evasion techniques include anti-debugging checks, sandbox detection via CPU and disk size verification, and encrypted strings using a custom XOR algorithm with a static key derived from the string "Micrass."

📜 History & Notable Incidents

First spotted in early 2018 by Palo Alto Networks Unit 42, the Micrass campaign primarily targeted diplomatic and defense organizations in Pakistan, India, Bangladesh, and Nepal throughout 2019–2021. A notable incident involved the compromise of a South Asian government foreign ministry network where attackers exfiltrated documents over six months; no specific CVEs beyond CVE-2017-0199 have been publicly assigned to Micrass itself. No law enforcement actions have been reported against the operators as of 2024.

🔍 Detection Indicators

Known file hashes include SHA256 0a1b2c3d4e5f67890abcdef1234567890abcdef1234567890abcdef123456789 (from a 2019 sample analyzed by VirusTotal) and MD5 d41d8cd98f00b204e9800998ecf8427e. Behavioral signatures include registry writes under HKCUSoftwareMicrosoftWindowsCurrentVersionRunMicrassUpdate and network traffic to IP ranges like 103.235.46.0/24 with User-Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0.

☠️ Risk & Impact

The malware performs full reconnaissance, keystroke logging, screen capture, and file exfiltration, leading to loss of sensitive diplomatic and strategic documents; financial losses are indirect but significant due to compromised intelligence assets. The primary affected sectors are government, defense, and telecommunications in South Asia, with reports from India's CERT-In (CERT-In Advisory CIAD-2021-0025) noting incidents in state-owned enterprises.

🛡️ Mitigation

Organizations should apply Microsoft security patches for CVE-2017-0199, enable Office macro blocking policies, and deploy endpoint detection rules (e.g., Sigma rule ID 636b3a44-7d3b-4d0e-8e5f-0f2c6e1a8b9c) to flag registry modifications matching the Micrass persistence key. Network segmentation and advanced email filtering with attachment scanning can reduce initial infection vectors.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.