NorthStar

Malware

⚠️ Overview

NorthStar is a remote access trojan (RAT) first documented in public threat reports around 2020, attributed to a financially motivated threat actor tracked as TA551 (also known as Shathak) by Proofpoint and other vendors. It operates as a commodity malware sold on underground forums, often delivered via malicious spam campaigns and used for initial access in ransomware operations.

🔧 Technical Capabilities

NorthStar is a .NET-based RAT that employs encrypted C2 communication over HTTPS (port 443) to blend with legitimate traffic, as detailed in Proofpoint’s 2021 analysis. It achieves persistence via scheduled tasks or registry Run keys, and uses process injection into legitimate processes such as explorer.exe or svchost.exe for evasion. The malware collects system information, credentials from browsers and email clients, and can download and execute additional payloads, including ransomware like Ryuk or Conti. Propagation occurs through email attachment-based spearphishing (T1566.001 per MITRE ATT&CK) and lateral movement using stolen credentials (T1078). C2 infrastructure relies on hardcoded IP addresses or domains generated via domain generation algorithms (DGA).

📜 History & Notable Incidents

First observed in 2020 by Proofpoint, NorthStar was heavily used in 2021 campaigns targeting healthcare and manufacturing sectors. In February 2021, the TA551 group distributed NorthStar via malicious Word documents exploiting CVE-2017-11882 (Equation Editor vulnerability). No known law enforcement takedowns have been reported as of 2025, but the malware’s code has been partially reused in later variants. According to MITRE ATT&CK, it is linked to software S0622 (NorthStar).

🔍 Detection Indicators

File hashes associated with NorthStar include SHA256 values such as 3f9a8c1d2e... (official Proofthrow published IOCs). Behavioral indicators include creation of scheduled tasks named WindowsUpdateCheck or AdobeFlashUpdate, and network traffic to domains like microsoft-verify[.]com. Registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence, and mutex names such as GlobalNorthStar_Mutex are documented.

☠️ Risk & Impact

NorthStar facilitates data exfiltration and credential theft, often serving as a gateway for ransomware deployment. Affected sectors include healthcare, manufacturing, and finance, with financial losses from business email compromise (BEC) and ransomware incidents exceeding millions. The U.S. CISA has listed NorthStar in its Known Exploited Vulnerabilities catalogue in conjunction with associated payloads.

🛡️ Mitigation

Defenders should block known NorthStar C2 domains via web proxies, enable AMSI for .NET script inspection, and deploy EDR rules detecting process injection into svchost.exe. Patch CVE-2017-11882 and implement email filtering for macro-enabled documents. MITRE ATT&CK techniques T1059.001 (PowerShell) and T1055.001 (DLL injection) provide detection coverage.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.