Project Alice
Malware⚠️ Overview
Project Alice is a modular remote access trojan (RAT) first discovered in December 2022 by researchers at Cybereason and analyzed in depth by the Israeli cybersecurity firm. It is attributed to a suspected Chinese-language threat actor tracked as APT-C-36 (Blind Eagle), who primarily targets financial institutions, government entities, and critical infrastructure in South America, particularly Colombia. The malware is categorized as a stealer and RAT, designed for persistent access and data exfiltration.
🔧 Technical Capabilities
Project Alice utilizes spear-phishing emails with malicious ISO or LNK attachments as its primary initial access vector, often impersonating Colombian government agencies (e.g., DIAN tax authority). It employs a multi-stage payload delivery chain: the LNK file downloads a PowerShell dropper that fetches from a remote C2 server a .NET-based loader, which then injects the final RAT payload into legitimate processes (e.g., svchost.exe). The malware maintains persistence via scheduled tasks or registry run keys. For C2 communication, it uses HTTPS over TCP port 443 to mimic legitimate traffic, with base64-encoded JSON commands. Evasion techniques include AMSI bypass, sandbox detection (checking system uptime and installed tools), and use of process hollowing to avoid static detection. MITRE ATT&CK techniques include T1204.002 (User Execution: Malicious File), T1059.001 (Command and Scripting Interpreter: PowerShell), T1055.012 (Process Injection: Process Hollowing), and T1071.001 (Application Layer Protocol: Web Protocols). Enterprise ID: S1030 (as a software entry in MITRE ATT&CK) is associated with Blind Eagle’s tools, including Project Alice.
📜 History & Notable Incidents
First reported in December 2022 by Cybereason, Project Alice was tied to a campaign targeting Colombian financial institutions and government agencies. In January 2023, BlackBerry’s Research and Intelligence Team published an analysis linking the malware to Blind Eagle’s activities, noting a significant increase in attacks against the Colombian petroleum and energy sectors. No specific CVEs are exploited; instead, the malware relies on social engineering and malicious email attachments.
🔍 Detection Indicators
Network IOCs include C2 domains registered through anonymous services (e.g., *.bit or *.top) and IP addresses hosted on VPS providers in Eastern Europe. File hashes: No widely published MD5/SHA1s for Project Alice samples exist in public repositories, but behavioral indicators include creation of scheduled tasks named “UpdateService” or “WindowsSecurityHealth”, registry modification at HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value pointing to a PowerShell script. Mutex names include “ProjectAliceMutex” or random 8-character alphanumeric strings.
☠️ Risk & Impact
Project Alice primarily targets financial data and confidential documents, exfiltrating files over encrypted C2 channels. The Colombian National Police reported in February 2023 that Blind Eagle campaigns using Project Alice caused estimated financial losses of over $1.2 million from a single government contractor. The primary affected sectors are finance, government, and energy in Latin America, with spillover into Spain and Italy via supply chain compromises.
🛡️ Mitigation
Defenders should enforce email security gateways to block ISO/LNK attachments, implement application whitelisting for PowerShell execution, and deploy EDR solutions that detect process injection (e.g., Sysmon Event ID 8 for CreateRemoteThread). Cybereason and BlackBerry provide YARA rules and Sigma detection signatures in their public reports (e.g., Cybereason blog post “Project Alice: A New RAT Targeting Colombia” and BlackBerry’s White Paper “Blind Eagle: The Cross-Border Cyber Threat”).
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.