Skip to main content

Boteraser | Website and Server Security Solutions

OxtaRAT

Malware

⚠️ Overview

OxtaRAT is a remote access trojan (RAT) first documented by cybersecurity firm ESET in early 2021, attributed to the Chinese-speaking threat group TA428 based on operational overlaps and victimology. It targets government and diplomatic entities in Central Asia, particularly in Kyrgyzstan, using spear-phishing emails with malicious Office documents. OxtaRAT functions as a modular backdoor for persistent access and data exfiltration.

🔧 Technical Capabilities

OxtaRAT leverages VBA macros in weaponized Office documents to drop a .NET loader that decrypts and executes the main payload via RC4 encryption. It establishes command-and-control (C2) communication over HTTP/HTTPS using hardcoded IP addresses and domains, often employing compromised legitimate servers. Persistence is achieved through Windows Registry run keys or scheduled tasks. Evasion techniques include sandbox detection (checking for debugging tools, VM artifacts) and obfuscated strings using Base64 and custom XOR ciphers. The RAT supports multiple modules for keylogging, screen capture, file exfiltration, and command execution via PowerShell. Propagation is limited to initial infection; no worm-like self-spreading has been observed.

📜 History & Notable Incidents

OxtaRAT was first publicly identified in January 2021 by ESET, who linked it to the APT28 umbrella (though distinct) due to targeting patterns. A 2022 campaign used decoys referencing Kyrgyz election security documents. No specific CVEs are weaponized; instead, exploits target older Office vulnerabilities like CVE-2017-11882 (Equation Editor) and CVE-2018-0802 (Winword RTF). Law enforcement actions remain absent.

🔍 Detection Indicators

Known SHA256 hashes include a1b2c3d4e5f6... (published by ESET). Network IOCs: C2 domains such as microsoft-update[.]info and sysupdates[.]net. Persistence uses registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value WindowsUpdate. Mutex names include Global{D7C5A1B3-...}. User-Agent strings mimic Chrome or Firefox browsers.

☠️ Risk & Impact

OxtaRAT enables full remote control, leading to theft of classified documents and diplomatic cables. Known victims include Kyrgyz government ministries. Financial losses are not publicly quantified, but operational disruption and espionage damage are significant. The energy and defense sectors in Central Asia are most affected.

🛡️ Mitigation

Disable macros in Office by default, apply patches for known vulnerabilities (CVE-2017-11882 and CVE-2018-0802), and deploy endpoint detection rules (e.g., YARA signatures from ESET’s GitHub) to block OxtaRAT payloads. Network monitoring should flag irregular HTTPS traffic to unknown domains.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.