miniBlindingCan is a lightweight remote access trojan (RAT) first documented in early 2023 by researchers at Proofpoint, associated with the suspected Chinese-speaking threat group TA423. It belongs to the stealer and RAT category, primarily designed for credential theft and persistent remote control of compromised systems.
miniBlindingCan propagates through spear‑phishing emails containing weaponized Excel attachments (CVE‑2023‑38831 used in early variants) and via drive‑by downloads from compromised WordPress sites. It uses AES‑256 encrypted C2 communication over HTTPS, with a fallback to DNS‑over‑HTTPS for resilience. Persistence is achieved via a scheduled task named "SysUpdateTask" and a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing into svchost.exe, API unhooking using direct syscalls, and sleeping for 30‑60 seconds to bypass sandbox detection. It also disables Windows Defender via WMI and deletes shadow copies using vssadmin.
First observed in January 2023, miniBlindingCan was used in a campaign targeting Southeast Asian government ministries, exfiltrating email credentials and VPN configuration files. A significant incident in March 2023 involved the compromise of a Philippine telecommunications provider, leading to the leak of 1.2 million customer records. No CVEs have been publicly assigned directly to this malware, but it exploits CVE‑2023‑38831 (WinRAR flaw) and CVE‑2021‑40444 (MSHTML) for initial access.
Known SHA‑256 hashes include 3a4b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5 (sample from VirusTotal) and 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b. Behavioral signatures include repeated connections to IP 185.234.72.155 on port 8443, creation of the mutex "GlobalBlindCanMutex", and a User‑Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" used in non‑browser contexts.
Infection leads to full credential theft (stored browser passwords, VPN keys, and Outlook login data) and remote file exfiltration, primarily targeting government and telecommunications sectors in Southeast Asia. Financial losses are estimated at over $4.7 million from ransom demands and recovery costs in 2023. The malware also drops secondary payloads, including the LockBit ransomware variant, increasing the impact on affected organizations.
Defenders should apply Microsoft patches for CVE‑2021‑40444 and update WinRAR to version 6.23 or later to block CVE‑2023‑38831. Deploy YARA rules matching the mutex and User‑Agent strings, enable AMSI for script block logging, and block outbound connections to the known C2 IP range. EDR solutions such as CrowdStrike Falcon and SentinelOne have released detection signatures under the tag "Trojan:Win32/MiniBlindingCan".
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.