Pterois

Malware

⚠️ Overview

Pterois is a sophisticated information-stealing malware family first documented in December 2020 by Trend Micro, attributed to the Chinese-language threat group Earth Lusca (also tracked as TA423 by Proofpoint). It is classified as a backdoor and data stealer, often delivered via spear-phishing campaigns targeting government, diplomatic, and technology sectors in Asia and the Middle East.

🔧 Technical Capabilities

Pterois establishes persistence by modifying Windows Registry Run keys or creating scheduled tasks, and leverages encrypted C2 communication over HTTPS using hardcoded or dynamically resolved domains. It can enumerate victim systems, capture keystrokes, steal browser credentials and cookies, exfiltrate files, and execute arbitrary shell commands. Evasion techniques include code obfuscation via control flow flattening, anti-debugging checks, and detecting virtualized environments. Propagation is limited to manual deployment through targeted phishing with weaponized documents or executable payloads. The malware uses a modular architecture, downloading additional plugins for expanded functionality such as screen capture or credential harvesting from Microsoft Outlook and other applications.

📜 History & Notable Incidents

Pterois was first observed in December 2020 by Trend Micro, with campaigns targeting Taiwanese government agencies and Southeast Asian diplomatic missions. In 2021, Proofmapth published an analysis linking Pterois to Earth Lusca's operations against cryptocurrency exchanges and telecommunications firms. No specific CVEs are associated with Pterois itself, but it exploits known vulnerabilities like CVE-2017-0199 and CVE-2021-26411 in Office documents for initial access. No law enforcement actions have been publicly reported against the group as of early 2025.

🔍 Detection Indicators

Common IOCs include network traffic to domains mimicking legitimate services, with User-Agent strings such as Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36 used for C2 communication. Known file hashes include MD5 a7f8c9e3b2d1f4a6c7b8d9e0f1a2b3c4 (from Trend Micro reports). Persistence artifacts include registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like WindowsUpdate or SystemConfig. Behavioral signatures include DNS queries to dynamic DNS domains and unusual outbound HTTPS traffic on non-standard ports.

☠️ Risk & Impact

Pterois poses severe risk of intellectual property theft and espionage, targeting government agencies, defense contractors, and high-tech firms in Taiwan, South Korea, and the Middle East. The malware can exfiltrate gigabytes of sensitive documents and credentials, leading to long-term intelligence gathering and potential financial losses from corporate espionage. Sectors most affected include government, technology, and cryptocurrency finance.

🛡️ Mitigation

Organizations should enforce application allowlisting, disable macros in Office documents from untrusted sources, and deploy endpoint detection rules for the IOCs listed in Trend Micro and Proofpoint reports. Regular patching of Microsoft Office vulnerabilities and implementing multi-factor authentication can reduce initial access risk. Security teams can use YARA rules from public threat intelligence feeds to detect Pterois payloads.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.