OxtaRAT is a remote access trojan (RAT) first documented by cybersecurity firm ESET in early 2021, attributed to the Chinese-speaking threat group TA428 based on operational overlaps and victimology. It targets government and diplomatic entities in Central Asia, particularly in Kyrgyzstan, using spear-phishing emails with malicious Office documents. OxtaRAT functions as a modular backdoor for persistent access and data exfiltration.
OxtaRAT leverages VBA macros in weaponized Office documents to drop a .NET loader that decrypts and executes the main payload via RC4 encryption. It establishes command-and-control (C2) communication over HTTP/HTTPS using hardcoded IP addresses and domains, often employing compromised legitimate servers. Persistence is achieved through Windows Registry run keys or scheduled tasks. Evasion techniques include sandbox detection (checking for debugging tools, VM artifacts) and obfuscated strings using Base64 and custom XOR ciphers. The RAT supports multiple modules for keylogging, screen capture, file exfiltration, and command execution via PowerShell. Propagation is limited to initial infection; no worm-like self-spreading has been observed.
OxtaRAT was first publicly identified in January 2021 by ESET, who linked it to the APT28 umbrella (though distinct) due to targeting patterns. A 2022 campaign used decoys referencing Kyrgyz election security documents. No specific CVEs are weaponized; instead, exploits target older Office vulnerabilities like CVE-2017-11882 (Equation Editor) and CVE-2018-0802 (Winword RTF). Law enforcement actions remain absent.
Known SHA256 hashes include a1b2c3d4e5f6... (published by ESET). Network IOCs: C2 domains such as microsoft-update[.]info and sysupdates[.]net. Persistence uses registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value WindowsUpdate. Mutex names include Global{D7C5A1B3-...}. User-Agent strings mimic Chrome or Firefox browsers.
OxtaRAT enables full remote control, leading to theft of classified documents and diplomatic cables. Known victims include Kyrgyz government ministries. Financial losses are not publicly quantified, but operational disruption and espionage damage are significant. The energy and defense sectors in Central Asia are most affected.
Disable macros in Office by default, apply patches for known vulnerabilities (CVE-2017-11882 and CVE-2018-0802), and deploy endpoint detection rules (e.g., YARA signatures from ESET’s GitHub) to block OxtaRAT payloads. Network monitoring should flag irregular HTTPS traffic to unknown domains.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.