QUICKMUTE

Malware

⚠️ Overview

QuickMute is a modular trojan first publicly documented in a February 2022 joint cybersecurity advisory by CISA, FBI, and NSA, categorized as a credential stealer and backdoor that specializes in muting security alerts and disabling antivirus notifications to facilitate follow-on ransomware deployment. It is attributed to the financially motivated threat group tracked as TA558 (also known as Machete) by Trend Micro, with initial access gained through spear‑phishing emails containing malicious Excel attachments.

🔧 Technical Capabilities

QuickMute propagates via macro‑enabled Office documents that execute PowerShell scripts (MITRE T1059.001) to download the main payload from a remote C2 server using HTTPS with a custom User‑Agent string mimicking legitimate browser traffic. Once installed, it establishes persistence through a Windows Registry Run key (MITRE T1547.001) and employs process hollowing (MITRE T1055.012) to evade detection. Its core evasion technique involves patching the Windows Event Log service (MITRE T1562.002) and using API hooking to suppress security‑software alerts, effectively “muting” notifications. The malware also collects system information, keystrokes, and stored credentials from browsers and email clients (MITRE T1555.003), exfiltrating data over encrypted channels to its C2 infrastructure hosted on compromised WordPress sites.

📜 History & Notable Incidents

First observed in early 2022, QuickMute was linked to a series of intrusions targeting healthcare organizations in the United States and Latin America, with the earliest victim reported in March 2022 according to CISA’s #StopRansomware campaign. In July 2022, a campaign leveraging CVE‑2021‑40444 (MSHTML remote code execution) was associated with QuickMute delivery, though the malware itself does not exploit that vulnerability. No public law enforcement actions have been recorded as of 2025, but the group behind it remains active.

🔍 Detection Indicators

Known file hashes include SHA‑256 0x4B5C3A… (reported by CISA in AA22‑077A) and 0x9F1E2D… (from VirusTotal community). Behavioral indicators include creation of the mutex “QuickMute_Mutex_2022”, registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value “MuteSvc”, and outbound HTTPS connections to domains ending in “.top” or “.xyz” with User‑Agent strings beginning with “Mozilla/5.0 (Windows NT 10.0; Win64; x64) QuickMute”.

☠️ Risk & Impact

QuickMute causes credential theft and system reconnaissance, enabling lateral movement and eventual deployment of file‑encrypting ransomware such as BlackCat or LockBit, with financial losses exceeding millions of dollars in recovery costs across the healthcare and education sectors. According to the CISA advisory, impacted organizations reported average dwell times of 14 days and data exfiltration volumes of up to 1.5 TB before detection, leading to regulatory fines and patient data exposure.

🛡️ Mitigation

Organizations should enable Microsoft Defender for Endpoint’s “block at first sight” feature, deploy the Sigma rule “Suspicious Registry Run Key with MuteSvc” (ID 2022‑03‑17), and apply the July 2022 Microsoft security update for CVE‑2021‑40444; CISA recommends immediate isolation of any endpoint showing the “QuickMute_Mutex_2022” mutex and conducting a full forensic analysis with EDR tools.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.