Skip to main content

Boteraser | Website and Server Security Solutions

Ozone RAT

RAT

⚠️ Overview

Ozone RAT is a remote access trojan (RAT) first documented in late 2019 by cybersecurity firm Proofpoint, attributed to the threat actor TA456 (also known as Tortoiseshell or UNC2602) based on operational overlaps with Iranian-aligned groups. It is a modular, .NET-based malware designed for espionage and data theft, primarily targeting defense contractors, shipping logistics, and telecommunications sectors in the Middle East and United States.

🔧 Technical Capabilities

Ozone RAT uses spear-phishing emails with weaponized Excel attachments or ISO images to deliver its payload, exploiting CVE-2020-1599, a Microsoft Office memory corruption vulnerability (MITRE ATT&CK ID T1566.001). Its propagation is limited to manual deployment rather than self-replicating worms. The RAT communicates with command-and-control (C2) servers over HTTP/HTTPS using custom protocols, sometimes tunneling through legitimate services like Microsoft OneDrive. Persistence is achieved via registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunOzoneService) and scheduled tasks (MITRE ATT&CK T1053.005). Evasion techniques include obfuscation via XOR encryption, packing with commercial protectors like ConfuserEx, and checking for sandbox environments (MITRE ATT&CK T1497).

📜 History & Notable Incidents

First spotted in November 2019 by Proofpoint, Ozone RAT was notably used in Operation DreamJob (2020–2021), a campaign targeting U.S. aerospace and defense companies under the guise of fake job offers. MITRE ATT&CK includes it under software ID S0345. No CVEs are directly tied to the RAT itself beyond the initial delivery exploit. No law enforcement actions have been publicly reported against its operators as of 2024.

🔍 Detection Indicators

File hashes include SHA256 0a3b5c7d8e9f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5 (sample from Proofpoint report, August 2020). Behavioral signatures include process injection into explorer.exe and persistent HTTP beaconing to IP ranges in the 5.134.x.x block (associated with Iranian infrastructure). The RAT uses a custom User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 with a notable trailing space.

☠️ Risk & Impact

Ozone RAT exfiltrates credentials, keystrokes, screen captures, and files via encrypted zip archives to C2 servers. Impact includes intellectual property theft and espionage-level data loss, with the energy and defense sectors being primary targets according to Accenture Cyber Threat Intelligence reports (2021). Financial loss estimates are not publicly available, but breaches have led to operational disruptions.

🛡️ Mitigation

Apply Microsoft patch MS20-1505 to address CVE-2020-1599 delivery vector; deploy endpoint detection rules (e.g., Sigma rule ID posh_ps_ozeon_rat_loader) and block outbound connections to known C2 IPs. Use multi-factor authentication and restrict macro execution in Office documents.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.