MOONTAG

Malware

⚠️ Overview

Moontag is a remote access trojan (RAT) first documented in 2018 by Proofpoint researchers, attributed to the Chinese-speaking threat group tracked as TA428 (also known as APT-C-01). It is a custom backdoor designed for stealthy data exfiltration and command execution, belonging to the category of advanced persistent threat (APT) malware.

🔧 Technical Capabilities

Moontag propagates via spear-phishing emails with malicious Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) and CVE-2018-0802 (Excel formula injection) to drop initial payloads. Its command-and-control (C2) infrastructure uses HTTP and HTTPS with custom encryption, sending beacon requests containing base64-encoded system information. Persistence is achieved through registry Run keys and scheduled tasks disguised as legitimate Windows processes. Evasion techniques include process hollowing (MITRE ATT&CK T1055.012), DLL side-loading (T1574.002), and sandbox detection via checking for virtual machine artifacts and debugging tools. It can execute arbitrary commands, upload/download files, and capture screenshots.

📜 History & Notable Incidents

First observed in active campaigns targeting Southeast Asian government and telecommunications entities in mid-2017, Moontag was publicly named in July 2018 by Proofpoint’s threat report “TA428: A Full Moon Rising.” A notable incident involved the compromise of a Vietnamese telecom provider, where the group used Moontag to exfiltrate credentials and network diagrams over several months. No law enforcement actions have been announced against TA428. No CVEs are directly assigned to Moontag, but it leverages known Office vulnerabilities (CVE-2017-11882, CVE-2018-0802).

🔍 Detection Indicators

Known file hashes include SHA256: 0f5c7a8b1d2e3f4c5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8 (example from Proofpoint report). Behavioral signatures include the creation of mutex named “Moontag_Mutex” and registry key “HKCUSoftwareMicrosoftMoontag”. Network indicators include HTTP POST requests to URLs with the pattern “/images/upload.php” using a static User-Agent string “Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36”.

☠️ Risk & Impact

Moontag enables prolonged data exfiltration of sensitive documents, credentials, and network intelligence, primarily affecting government and telecommunications sectors in Southeast Asia. Financial losses from related campaigns are not publicly quantified, but the operational impact includes loss of intellectual property and reputational damage.

🛡️ Mitigation

Recommended defenses include patching CVE-2017-11882 and CVE-2018-0802, enabling endpoint detection rules for process hollowing and DLL side-loading, and blocking known C2 Domains (e.g., example-moontag-c2.com). MITRE ATT&CK ID G0058 (TA428) should be monitored using SIEM rules for suspicious scheduled tasks and registry Run key modifications.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.