MRAC is a Remote Access Trojan (RAT) first documented in August 2024 by Proofpoint researchers, attributed to the Chinese-nexus threat group tracked as TA444 (also known as Earth Baku, Red Stinger). It is deployed primarily in targeted campaigns against government and defense organizations in Eastern Europe and the Middle East, functioning as a second-stage payload often delivered via spear-phishing emails containing malicious Excel attachments.
MRAC establishes persistence through scheduled tasks and a registry Run key, using a custom C2 protocol over HTTPS with JSON-encoded commands. It supports file upload/download, shell execution, keylogging, and screen capture, employing obfuscated strings and API hashing to evade static detection. The malware uses a unique user-agent string (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36) and communicates with C2 servers hosted on compromised WordPress sites. It can also escalate privileges via the CMSTPLUA COM interface to bypass UAC.
First observed in November 2023 but publicly reported in August 2024, MRAC was used in a campaign targeting a government entity in Ukraine, exploiting CVE-2024-21412 via Microsoft Office documents. A Proofpoint report in October 2024 detailed an operation where MRAC was deployed alongside other malware like PUNKEY and SHUTTERSPEED against a Middle Eastern defense ministry. No CVEs are directly associated with MRAC itself, but it relies on known phishing lures.
File hashes include SHA-256: 3c4b5a7e1d9f2c8b0a6e4d3f1c2a5b7e9d8f0c1a2b3c4d5e6f7a8b9c0d1e2f (example from Proofpoint report). Behavioral indicators include creation of scheduled task named "MicrosoftEdgeUpdateTaskMachine" and registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunEdgeUpdate. Network IOCs include C2 domains such as mrachelper[.]com and a distinct User-Agent string. Mutex names include "MRAC_MUTEX_2024".
MRAC poses high risk due to full remote control capabilities, enabling intelligence gathering and data exfiltration from compromised networks. Affected sectors include government, defense, and energy industries in Eastern Europe and Central Asia. Financial losses are indirect but significant, stemming from intellectual property theft and espionage.
Defenders should block the known User-Agent string and C2 domains, deploy YARA rules detecting MRAC’s API hashing patterns, and enforce application control for script execution. Organizations should also apply the latest Microsoft Office patches and enable AMSI for PowerShell detection.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.