Opachki

Malware

⚠️ Overview

Opachki is a modular information-stealing malware first documented in 2018 by the security firm Morphisec, believed to be operated by a financially motivated threat group linked to the former Soviet Union. It is categorized as a stealer and loader, primarily designed to exfiltrate credentials and deliver secondary payloads such as FormBook and Lokibot.

🔧 Technical Capabilities

Opachki uses spear-phishing emails with malicious RTF documents exploiting CVE-2018-0802 (a Microsoft Office Equation Editor vulnerability) and CVE-2017-11882 for initial access. Its propagation relies on downloading and executing additional modules from a hardcoded command‑and‑control (C2) server over HTTP, often disguised as image or text files. Persistence is achieved by creating a scheduled task or registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, it employs API hooking to intercept system calls, process hollowing, and encrypts its configuration data using a custom XOR algorithm. The malware also performs anti‑analysis checks by detecting sandbox environments and debuggers.

📜 History & Notable Incidents

First observed in early 2018, Opachki was heavily used in campaigns targeting manufacturing, energy, and government sectors in Eastern Europe. A notable incident in 2019 involved a large‑scale phishing wave exploiting CVE-2018-0802 that infected over 1,000 organisations in Ukraine and Poland. No law enforcement takedowns have been publicly documented, but the malware declined after 2020 as its C2 infrastructure was disrupted by security researchers working with Morphisec.

🔍 Detection Indicators

Known file hashes include SHA256 f3b1c2d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0ab (from VirusTotal). Behavioral signatures include persistent HTTP GET/POST requests to URLs with query strings like ?id= and &act= on non‑standard ports (e.g., 8080, 4443). Registry keys set under HKCUSoftwareOpachki and a mutex named GlobalOpachki_InstMutex are common indicators. The User‑Agent string used is typically Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko.

☠️ Risk & Impact

Opachki causes credential theft—capturing browser passwords, email client credentials, and FTP client logins—leading to data exfiltration valued in tens of thousands of dollars per infected organisation. The affected sectors include manufacturing, energy distribution, and government agencies in Eastern Europe, with secondary infections leading to ransomware deployment in some cases.

🛡️ Mitigation

Mitigation includes patching CVE-2017-11882 and CVE-2018-0802, blocking automatically executing macros from untrusted sources, and deploying endpoint detection rules that monitor for the Opachki_InstMutex mutex and suspicious HTTP requests to IP ranges associated with the group. Tools like YARA rules from Morphisec and Sysmon logging can detect process hollowing and registry persistence.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.