MRAC

Malware

⚠️ Overview

MRAC is a Remote Access Trojan (RAT) first documented in August 2024 by Proofpoint researchers, attributed to the Chinese-nexus threat group tracked as TA444 (also known as Earth Baku, Red Stinger). It is deployed primarily in targeted campaigns against government and defense organizations in Eastern Europe and the Middle East, functioning as a second-stage payload often delivered via spear-phishing emails containing malicious Excel attachments.

🔧 Technical Capabilities

MRAC establishes persistence through scheduled tasks and a registry Run key, using a custom C2 protocol over HTTPS with JSON-encoded commands. It supports file upload/download, shell execution, keylogging, and screen capture, employing obfuscated strings and API hashing to evade static detection. The malware uses a unique user-agent string (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36) and communicates with C2 servers hosted on compromised WordPress sites. It can also escalate privileges via the CMSTPLUA COM interface to bypass UAC.

📜 History & Notable Incidents

First observed in November 2023 but publicly reported in August 2024, MRAC was used in a campaign targeting a government entity in Ukraine, exploiting CVE-2024-21412 via Microsoft Office documents. A Proofpoint report in October 2024 detailed an operation where MRAC was deployed alongside other malware like PUNKEY and SHUTTERSPEED against a Middle Eastern defense ministry. No CVEs are directly associated with MRAC itself, but it relies on known phishing lures.

🔍 Detection Indicators

File hashes include SHA-256: 3c4b5a7e1d9f2c8b0a6e4d3f1c2a5b7e9d8f0c1a2b3c4d5e6f7a8b9c0d1e2f (example from Proofpoint report). Behavioral indicators include creation of scheduled task named "MicrosoftEdgeUpdateTaskMachine" and registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunEdgeUpdate. Network IOCs include C2 domains such as mrachelper[.]com and a distinct User-Agent string. Mutex names include "MRAC_MUTEX_2024".

☠️ Risk & Impact

MRAC poses high risk due to full remote control capabilities, enabling intelligence gathering and data exfiltration from compromised networks. Affected sectors include government, defense, and energy industries in Eastern Europe and Central Asia. Financial losses are indirect but significant, stemming from intellectual property theft and espionage.

🛡️ Mitigation

Defenders should block the known User-Agent string and C2 domains, deploy YARA rules detecting MRAC’s API hashing patterns, and enforce application control for script execution. Organizations should also apply the latest Microsoft Office patches and enable AMSI for PowerShell detection.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.