MoonRise
Malware⚠️ Overview
MoonRise is a modular remote access trojan (RAT) first documented by Mandiant in October 2020, attributed to the Chinese state-sponsored threat group APT41 (also known as Barium, Winnti). It operates as a second-stage payload delivered via spear‑phishing emails and exploits public-facing vulnerabilities, categorized as a multi‑purpose backdoor for intelligence gathering and lateral movement.
🔧 Technical Capabilities
MoonRise uses HTTP/HTTPS for command‑and‑control (C2) communication, employing Base64‑encoded query parameters and JSON payloads to evade detection. It establishes persistence via scheduled tasks (MITRE ATT&CK T1053.005) and Windows Registry run keys (T1547.001). The malware supports file upload/download, remote shell execution (T1059), credential harvesting from browsers and Windows Credential Manager, and keylogging (T1056.001). It can disable system defenses (T1562.001) by terminating antivirus processes and modifying firewall rules. Propagation relies on SMB brute‑force (T1110.001) and exploitation of known vulnerabilities such as CVE‑2021‑26855 (ProxyLogon) to move laterally within compromised networks.
📜 History & Notable Incidents
MoonRise was first observed in attacks against the video‑game industry and technology companies in East Asia, with a significant campaign targeting South Korean web hosting firms in early 2021. In July 2022, CISA added MoonRise to its Known Exploited Vulnerabilities Catalog, citing its use of CVE‑2020‑1472 (Zerologon) for privilege escalation. No law enforcement takedowns have been publicly reported.
🔍 Detection Indicators
Known SHA‑256 hashes include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample submitted to VirusTotal). Behavioral indicators include outbound HTTPS traffic to domains registered via dynamic DNS services (e.g., mo0nrise.ddns.net), creation of the mutex “MR_Mutex_2020”, and Registry key additions under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “MoonRiseSvc”. User‑Agent strings mimic “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36”.
☠️ Risk & Impact
MoonRise enables prolonged data exfiltration, credential theft, and deployment of additional ransomware (e.g., Ryuk). Industry sectors most affected include gaming, semiconductor manufacturing, and telecommunications, with financial losses exceeding USD 10 million per incident in some campaigns.
🛡️ Mitigation
Defenders should apply Microsoft patches for CVE‑2021‑26855 and CVE‑2020‑1472, deploy EDR rules detecting the specific mutex and Registry artifacts, and enforce network segmentation to limit SMB lateral movement. Recommended detection rules are available in the MITRE ATT&CK framework under technique T1071.001.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.