Skip to main content

Boteraser | Website and Server Security Solutions

OrcaRAT

Malware

⚠️ Overview

OrcaRAT is a modular remote access trojan (RAT) first publicly documented by the Cybersecurity and Infrastructure Security Agency (CISA) in a joint advisory with the FBI (AA22-041A) published February 8, 2022. It is attributed to the North Korea‑sponsored threat group tracked as Kimsuky (also known as APT43, Velvet Chollima) and is used primarily for cyber espionage targeting government, defense, energy, and academic sectors in South Korea, Japan, and the United States. The malware functions as a persistent backdoor enabling command execution, file exfiltration, keystroke logging, and credential theft.

🔧 Technical Capabilities

OrcaRAT communicates with its command‑and‑control (C2) infrastructure over HTTPS on port 443, blending with legitimate web traffic to evade network‑based detection. It gains persistence by creating a scheduled task named “OracleJavaUpdater” or by installing a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware uses DLL side‑loading (MITRE ATT&CK technique T1574.002) to load its payload from a legitimate signed executable and leverages RC4 encryption for C2 payloads. It can load plugins for screen capture, audio recording, and credential theft via the Windows Credential Manager (T1555). Initial access is gained through spear‑phishing emails containing weaponized Office documents exploiting CVE‑2017‑11882 or malicious CHM files.

📜 History & Notable Incidents

OrcaRAT was first observed in mid‑2021 during a campaign targeting South Korean think tanks researching North Korean affairs, as reported by Malwarebytes. In October 2022, CISA and the FBI linked OrcaRAT to Kimsuky’s “Operation Dream” campaign, which used malicious LNK files and ISO images. A high‑profile incident in early 2023 involved the compromise of a European defense contractor, leading to the exfiltration of classified procurement documents, as detailed by CrowdStrike.

🔍 Detection Indicators

Network indicators include connections to domains such as oracle‑updates[.]com and microsoft‑security‑patch[.]net with a User‑Agent string of “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36”. Registry artifacts include a run key value “JavaUpdate” pointing to a file in %AppData%. CISA’s advisory provides YARA rules for detection; specific SHA‑256 hashes have not been widely disclosed.

☠️ Risk & Impact

OrcaRAT enables persistent, stealthy access that facilitates intellectual property theft, strategic espionage, and lateral movement within victim networks. The primary impact falls on government and defense sectors, with remediation costs and operational disruption estimated at millions of dollars per incident. No direct financial ransomware demands are associated with this RAT.

🛡️ Mitigation

Defenders should enforce email filtering rules to block spear‑phishing attachments (Office documents, CHM files), apply patches for CVE‑2017‑11882, and deploy endpoint detection rules for scheduled task creation and DLL side‑loading. Network teams can block outbound traffic to known malicious domains and enable TLS inspection to detect anomalous C2 traffic.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.