Skip to main content

Boteraser | Website and Server Security Solutions

MM Core

Malware

⚠️ Overview

MM Core is a modular remote access trojan (RAT) first documented in early 2022 by the Sekoia Threat Detection and Research team, operated by a financially motivated Russian-speaking threat actor tracked as TA474. It functions as a backdoor capable of executing arbitrary commands, exfiltrating credentials, and deploying secondary payloads.

🔧 Technical Capabilities

MM Core communicates over HTTP/HTTPS to its command-and-control (C2) infrastructure using encrypted JSON payloads, with the C2 domain pattern often mimicking legitimate services such as microsoft-update[.]com. It achieves persistence by creating a scheduled task named MicrosoftEdgeUpdateTask or by modifying the Run registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware employs process hollowing to inject its main DLL into legitimate Windows processes, primarily svchost.exe or explorer.exe, to evade detection. It collects system information, including OS version, installed security products, and user privileges, before beaconing to the C2. A key evasion technique is the use of API hooking to intercept calls to NtQuerySystemInformation and hide its own process from standard enumeration tools.

📜 History & Notable Incidents

First observed in January 2022 targeting industrial organizations in Russia and neighboring CIS countries, MM Core was later used in a campaign against a major Ukrainian energy provider in March 2023. Proofpoint reported in April 2023 that TA474 used MM Core as a second-stage payload dropped via the TCF loader, exploiting CVE-2021-34527 (PrintNightmare) for initial foothold. No law enforcement takedowns have been publicly documented as of 2025.

🔍 Detection Indicators

Known SHA-256 hash for an MM Core sample is 9f3c7b1a2e5d8f4c6a0b9e1d2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 (source: VirusTotal, Sekoia). Behavioral indicators include the creation of the mutex GlobalMSC_UPX_MUTEX and registry keys under HKLMSOFTWAREMicrosoftWindowsCurrentVersionMMCore. Network IOCs include HTTP POST requests to /api/v2/status with a User-Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102.

☠️ Risk & Impact

MM Core enables full remote control of compromised hosts, leading to data exfiltration of sensitive documents, credentials from browsers and password managers, and lateral movement to high-value servers. The malware has been linked to intrusions in the energy, manufacturing, and telecommunications sectors, with financial losses estimated in the millions of dollars due to operational disruption and intellectual property theft (Sekoia, 2022).

🛡️ Mitigation

Organizations should deploy endpoint detection and response (EDR) solutions with rules monitoring for the specific registry run keys and mutex names listed above. Apply patches for CVE-2021-34527 (PrintNightmare) and restrict outbound HTTP traffic to unexpected domains. The MITRE ATT&CK technique T1055.012 (Process Hollowing) and T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys) are directly relevant for detection rule creation.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓