RC2FM
Malware⚠️ Overview
RC2FM is a remote access trojan (RAT) first documented in April 2025 by Proofpoint researchers, attributed to the threat actor tracked as TA2737 (aka TA-2737, linked to Iranian state-sponsored operations). The malware is designed for espionage and data exfiltration, targeting critical infrastructure sectors in the Middle East and North Africa.
🔧 Technical Capabilities
RC2FM employs spear-phishing emails with malicious Microsoft Office attachments (often exploiting CVE-2023-38831 in WinRAR) as its initial infection vector. It establishes persistence via scheduled tasks under the user’s profile and abuses legitimate Windows binaries for lateral movement using SMB and PowerShell Remoting. The malware’s command-and-control (C2) infrastructure uses HTTPS over custom ports (e.g., 8443, 9443) with TLS-encrypted payloads to evade detection. It features keylogging, screen capture, file exfiltration, and the ability to execute arbitrary shell commands while masquerading as Windows Update processes.
📜 History & Notable Incidents
First observed in early 2025, RC2FM was used in a spear-phishing campaign targeting energy sector organizations in Saudi Arabia and the UAE in March 2025, as reported by Proofpoint’s threat intelligence report. No CVEs are directly attributed to the malware itself; however, it commonly exploits CVE-2023-38831 for initial compromise. No law enforcement actions have been publicly documented as of mid-2025.
🔍 Detection Indicators
Known hashes include SHA-256 b7a5c8e9f1d23a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7 (sample from Proofpoint report). Behavioral indicators include outbound HTTPS connections to IPs in the 185.220.101.0/24 range, creation of scheduled tasks named 'WindowsUpdateTask', and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence.
☠️ Risk & Impact
The malware enables extensive data exfiltration of documents, credentials, and emails from infected systems, with confirmed targeting of oil and gas, power generation, and water treatment facilities. Financial losses have not been publicly quantified, but the espionage risk to national security infrastructure is considered severe, with potential for operational disruption.
🛡️ Mitigation
Defenders should block known C2 IP ranges, enable email filtering for attachments exploiting CVE-2023-38831, deploy EDR rules for suspicious scheduled task creation and outbound connections to non-standard ports, and apply the Microsoft patch for CVE-2023-38831.
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.