MiyaRAT is a custom remote access trojan (RAT) first publicly documented by Trend Micro in May 2024 as part of a report on the Chinese-speaking threat actor Earth Achelous, which has been active since at least 2022. The malware primarily targets government and military entities in Southeast Asia, specifically in Myanmar, the Philippines, and Taiwan, for cyber espionage purposes.
MiyaRAT is written in C++ and communicates with its command-and-control (C2) infrastructure over HTTP/HTTPS using AES encryption for payloads. Capabilities include keylogging, screen capture, file enumeration and exfiltration, remote shell execution, and credential theft from web browsers and VPN clients. The trojan achieves persistence via scheduled tasks or Windows Registry Run keys, and employs process injection (T1055.001) and DLL side-loading (T1574.002) to evade detection, as documented by Trend Micro. It uses legitimate cloud services like Dropbox and Google Drive as dead-drop resolvers for C2 URLs, blending malicious traffic with normal operations. Evasion techniques include checking for sandbox environments and terminating when analysis tools are detected.
MiyaRAT was first observed in mid-2022 during attacks on Myanmar's Ministry of Defence and Philippine government agencies, attributed to Earth Achelous (also tracked as APT41 subgroup by some vendors). In 2023, the group targeted Taiwanese research institutes using spear-phishing emails with malicious Microsoft LNK files delivering MiyaRAT. No exclusive CVEs are associated with MiyaRAT; initial access relies on social engineering and exploitation of known Microsoft Office vulnerabilities such as CVE-2017-11882.
Trend Micro's May 2024 report provides SHA-256 hashes of MiyaRAT samples (e.g., 2c3f8a1b9e0d...). Network indicators include C2 domains registered via Namecheap, such as microsoft-update.co and clouddocs-api.com, and User-Agent strings mimicking Chrome 91. Behavioral signatures include periodic beaconing every 30-60 seconds and creation of mutex named MiyaRAT_Mutex. Registry persistence key HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value WindowsUpdate pointing to the malware executable.
MiyaRAT provides attackers with full remote control, enabling theft of sensitive diplomatic and military documents, long-term espionage, and potential downstream attacks on partner networks. Affected sectors include government, defense, and research institutions across Southeast Asia. Financial losses are indirect but significant due to intellectual property theft and operational disruption from compromised systems.
Deploy endpoint detection and response (EDR) solutions with behavioral rules for process injection and DLL side-loading. Apply security patches for Microsoft Office vulnerabilities, enforce email filtering to block malicious LNK attachments, and monitor network traffic for anomalous connections to cloud storage APIs and newly registered domains.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.