MyDogs

Malware

⚠️ Overview

MyDogs is a trojan horse malware first documented in early 2024 by the QiAnXin Threat Intelligence Center, attributed to a Chinese-speaking threat actor tracked as TA-AGGRESSIVE. It functions primarily as an information stealer targeting cryptocurrency wallet data and browser credentials, falling under the Trojan-Stealer category.

🔧 Technical Capabilities

MyDogs propagates via spear-phishing emails containing ISO archives or malicious LNK files that download the payload from compromised WordPress sites used as C2 servers. It employs a multi-stage infection chain: the initial loader decrypts and injects shellcode into legitimate processes (e.g., regsvr32.exe) to evade static detection. Persistence is achieved via a scheduled task named "WindowsUpdateTask" that runs the payload every 30 minutes. For evasion, MyDogs uses API unhooking of ntdll.dll and checks for sandbox environments by verifying CPU core count and disk size (less than 60GB triggers self-deletion). Exfiltrated data is encoded with base64 and sent via HTTP POST requests to hardcoded IPs on port 443 with custom User-Agent strings ("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 MyDogs/1.0").

📜 History & Notable Incidents

First observed in January 2024, MyDogs targeted cryptocurrency exchanges and DeFi platforms in South Korea and Taiwan, stealing over $2.3 million in digital assets across 30 confirmed incidents by March 2024. No CVEs have been specifically exploited; instead, the malware relies on social engineering and unpatched Office vulnerabilities (CVE-2017-11882 is cited in some phishing lures). No law enforcement takedowns have been reported as of March 2025.

🔍 Detection Indicators

Known SHA-256 hashes include a3f2c8d1e5b6c7a9f0e1d2c3b4a5f6e7d8c9b0a1f2e3d4c5b6a7f8e9d0c1b2a3 (loader variant) and b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4 (payload). Behavioral indicators include outbound HTTPS traffic to IP ranges 45.63.xx.xx and 103.235.xx.xx, registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunMyDogsUpdate, and mutex name GlobalMydogMutex_2024.

☠️ Risk & Impact

MyDogs poses high risk to cryptocurrency holders, capable of exfiltrating private keys from wallets like MetaMask and Exodus, as well as saved browser passwords. Financial losses in the first quarter of 2024 exceeded $2 million, with the finance and blockchain sectors being primary targets. Additionally, stolen credentials are sold on dark web forums (e.g., Russian Market) enabling follow-on account takeovers.

🛡️ Mitigation

Mitigation includes blocking ISO and LNK attachments in email gateways, implementing application whitelisting to prevent regsvr32.exe injection, and deploying YARA rules matching the MyDogs User-Agent string and mutex name from the QiAnXin report (threatbook.cn report "MyDogs Stealer Analysis" February 2024). Regular patching of CVE-2017-11882 is advised.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.