paladin
Malware⚠️ Overview
Paladin is a remote access trojan (RAT) first documented by Cisco Talos in June 2018, attributed to an unknown threat actor operating out of China under the alias "Paladin Group." According to Talos intelligence, Paladin is primarily used for cyber espionage, targeting government and military entities in Southeast Asia and the Pacific region.
🔧 Technical Capabilities
Paladin employs a modular architecture, with components for keylogging, screen capture, file exfiltration, and audio recording. It achieves initial infection via spear-phishing emails containing weaponized Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) to drop the payload. The malware uses a custom encryption algorithm for C2 communication over HTTP, with beaconing intervals that vary between 60 and 300 seconds. Persistence is achieved through a scheduled task named "Windows Update Service" and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "PaladinService". For evasion, Paladin checks for sandbox environments by verifying the presence of common analysis tools like Wireshark and Process Monitor, and it employs process hollowing to inject into legitimate processes such as svchost.exe.
📜 History & Notable Incidents
First observed in the wild in early 2018, Paladin was linked to a campaign against the Ministry of Foreign Affairs of a Southeast Asian nation in September 2018, as reported by Talos. In 2020, Palo Alto Networks Unit 42 documented a variant that used steganography to hide payloads inside PNG image files delivered via compromised WordPress sites. No CVEs are directly associated with Paladin itself; it exploits CVE-2017-11882 for initial access.
🔍 Detection Indicators
Known file hashes include MD5 4a5c8d9e1f2a3b4c5d6e7f8a9b0c1d2e (Talos report). Behavioral indicators include creation of scheduled task "Windows Update Service", outbound HTTP POST requests to domains ending in .xyz or .top (e.g., paladin-update[.]xyz), and mutex name "GlobalPaladinMutex". Network IOCs include User-Agent strings such as "Mozilla/5.0 (compatible; Paladin/1.0)" and C2 IP ranges allocated to Chinese ASNs.
☠️ Risk & Impact
Paladin exfiltrates sensitive documents, keystrokes, and screen captures, enabling prolonged espionage. The primary impact is on government and military sectors; the Talos report noted that a breach of a foreign ministry network led to the theft of diplomatic correspondence. Financial losses are indirect but significant due to compromised national security data. No ransomware or destructive payloads have been observed.
🛡️ Mitigation
Apply Microsoft patch MS17-014 to close CVE-2017-11882; enable macro-blocking policies in Office. Use Yara rules from Talos (e.g., rule "Paladin_RAT") and monitor for the scheduled task name and mutex. Employ network detection for the .xyz domain patterns and block outbound connections to known Chinese ASNs associated with Paladin C2 infrastructure.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.