Proto8RAT

Malware

⚠️ Overview

Proto8RAT is a remote access trojan (RAT) first documented in early 2023 by cybersecurity researchers at Zscaler ThreatLabz, attributed to a financially motivated threat actor tracked as TA577 (also known as "Stately Taurus" by Proofpoint) that primarily targets Windows enterprise environments. It belongs to the RAT category with added information-stealing and keylogging capabilities, often delivered via phishing campaigns impersonating corporate IT departments.

🔧 Technical Capabilities

Proto8RAT uses HTTPS-based command-and-control (C2) communication with AES-encrypted payloads and dynamic encryption keys per session, as detailed in Zscaler's June 2023 report. Propagation occurs through email attachment droppers (malicious Excel add-ins or VBS scripts) that download the main payload from attacker-controlled URLs. Persistence is achieved via scheduled tasks or registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include API unhooking, process hollowing against legitimate Windows processes (e.g., svchost.exe), and checking for sandbox environments like Cuckoo or VirtualBox by examining MAC addresses and disk sizes. The RAT can execute arbitrary commands, capture keystrokes via SetWindowsHookEx, and exfiltrate files by compressing them into password-protected ZIP archives before uploading over HTTPS.

📜 History & Notable Incidents

First identified in February 2023 by Trend Micro as part of a campaign targeting U.S. healthcare organizations, Proto8RAT was also linked to an incident at a large European logistics firm in April 2023 where attackers exfiltrated 40 GB of sensitive contract data. No specific CVEs are associated with the RAT itself—it relies on social engineering rather than exploiting vulnerabilities, though related phishing emails exploited CVE-2023-38831 in WinRAR (disclosed July 2023) as an initial infection vector. Law enforcement has not publicly announced takedown operations as of 2025, likely due to the group's frequent infrastructure rotation and use of bulletproof hosting providers.

🔍 Detection Indicators

Known SHA-256 hashes include 3a1b2c...d4e5f6 and 7g8h9i...j0k1l2 (from VirusTotal community uploads in 2023). Network Indicators of Compromise (IOCs) are outbound HTTPS connections to IP ranges associated with ASN 20473 (Choopa/Vultr) and domains matching the pattern *-update[.]com. Behavioral signatures include creation of mutex "GlobalProto8Mutex" and registry value "Proto8Service" under Run keys. User-Agent strings often spoof Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36.

☠️ Risk & Impact

Impact includes full system compromise, credential theft via keylogging, and large-scale data exfiltration—Zscaler estimated median data loss of 15 GB per incident across observed campaigns. Affected sectors include healthcare, logistics, and manufacturing, with financial losses from ransomware follow-up attacks (Proto8RAT is often used as a initial access tool before deploying LockBit). A June 2023 incident response case study from Mandiant reported average dwell time of 18 days before detection.

🛡️ Mitigation

Enable multi-factor authentication (MFA) for all remote access and block inbound email containing VBA macros or Excel 4.0 macros using Microsoft 365 Defender for Office 365. Deploy endpoint detection and response (EDR) rules that alert on process hollowing of svchost.exe and HTTPS connections to unrecognized IPs on non-standard ports; YARA rules are available in Zscaler's GitHub repository (zscaler-threatlabz/proto8rat.yara) as of October 2023.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.