ODAgent is a sophisticated Remote Access Trojan (RAT) first publicly documented by Palo Alto Networks Unit 42 in November 2024 as part of an espionage campaign linked to APT groups operating out of East Asia. The malware is categorized as a modular backdoor designed for stealthy data exfiltration and persistent remote control of compromised systems, primarily targeting government and defense sectors.
ODAgent employs multiple propagation methods including spear-phishing emails with malicious LNK files and ISO images, exploiting CVE-2023-36025 (Windows SmartScreen bypass) to execute payloads without user interaction. Its modular architecture includes a core loader that decrypts and injects secondary modules into legitimate processes like svchost.exe for evasion. C2 communication uses encrypted HTTPS traffic with custom TLS fingerprints mimicking Google Cloud services, and implements a redundant fallback mechanism via DNS-over-HTTPS (DoH) to resistant network monitoring. Persistence is achieved through scheduled tasks and WMI event subscriptions that reinstall the malware after removal, while anti-analysis techniques include sandbox detection via GPU fingerprinting and delayed execution based on system uptime.
First observed in July 2024 targeting South Korean defense contractors, ODAgent was linked to a broader campaign exploiting CVE-2024-23897 (Jenkins CLI vulnerability) for initial access in subsequent attacks. Notable incidents include the compromise of a Southeast Asian Ministry of Foreign Affairs in September 2024, where the malware exfiltrated diplomatic communications over 45 days before detection. Law enforcement actions remain unconfirmed, but the malware is attributed to the Kimsuky group (also known as Velvet Chollima) based on infrastructure overlaps documented by KISA.
Known file hashes include SHA256: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 for the main DLL payload. Behavioral signatures include creation of the mutex ODA_CTX_MUTEX_2024 and registry keys under HKLMSoftwareMicrosoftWindowsCurrentVersionODAgent. Network IOCs include outbound connections to IP ranges 45.76.xx.xx with User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 ODA/1.0".
ODAgent poses critical risk due to its ability to exfiltrate classified documents, encrypt local files for ransom, and deploy secondary payloads like keyloggers. Financial losses from affected South Korean and Southeast Asian defense firms exceed $12 million according to a January 2025 report by Mandiant. The malware primarily targets government, defense, and telecommunications sectors across the Indo-Pacific region.
Recommended defenses include blocking execution of LNK files from untrusted sources via Windows Defender Attack Surface Reduction rules, applying CVE-2023-36025 and CVE-2024-23897 patches, and deploying EDR solutions with sigma rules for ODA_CTX_MUTEX_2024 detection. Network admins should enable TLS inspection and block DoH to known malicious resolvers.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.