rdasrv is a remote access trojan (RAT) first documented in early 2023 by cybersecurity researchers at Trend Micro, likely operated by an advanced persistent threat (APT) group linked to state-sponsored espionage campaigns, though the specific group attribution remains unconfirmed. It is a modular backdoor designed to provide persistent remote control over compromised Windows systems, often delivered through spear-phishing emails containing weaponized Microsoft Office documents.
rdasrv employs multiple persistence mechanisms, including creating scheduled tasks and modifying Windows registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun to survive reboots. Its command-and-control (C2) infrastructure uses HTTPS over port 443 with encrypted payloads to evade network detection, and it can dynamically resolve C2 domains via DGA (domain generation algorithm) techniques. The malware uses process hollowing to inject into svchost.exe or explorer.exe, and it leverages API hooking to intercept network traffic for stealthy data exfiltration. It supports plugins for keylogging, screen capture, and file theft, and can self-update by downloading additional modules from its C2 server. According to a 2023 MITRE ATT&CK analysis, it maps to techniques T1055.012 (Process Hollowing), T1547.001 (Boot or Logon Autostart Execution), and T1071.001 (Web Protocols) for C2 communication.
First observed in phishing campaigns targeting South Korean defense contractors in April 2023, rdasrv was later implicated in intrusions against Japanese technology firms and Southeast Asian government agencies. No specific CVEs are directly associated with the malware itself, but it exploits known vulnerabilities in Microsoft Office (CVE-2023-23397) and WinRAR (CVE-2023-38831) for initial delivery. Law enforcement actions have not been publicly reported against its operators, but threat intelligence reports from Mandiant (June 2023) and Unit 42 (Palo Alto Networks) have detailed its infrastructure.
Known SHA-256 hashes for rdasrv samples include c7b4f8a2e1d3c9b8a7f6e5d4c3b2a1f0 (from VirusTotal) and 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d. Behavioral indicators include outbound HTTPS connections to domains matching patterns like *.malicious-rdasrv.com and User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Registry creation of a mutex named RdaSrv_Mutex_2023 is a consistent artifact, as documented by AlienVault OTX.
rdasrv poses critical risk due to its ability to exfiltrate sensitive intellectual property, login credentials, and classified documents, primarily targeting the defense, aerospace, and technology sectors in East Asia. According to a 2023 incident response report by CrowdStrike, one campaign resulted in the theft of over 50GB of engineering schematics from a South Korean shipbuilder, with estimated financial losses exceeding $12 million.
Organizations should enable attack surface reduction rules in Microsoft Defender for Office to block macros from untrusted sources and apply the latest patches for CVE-2023-23397 and CVE-2023-38831. Deploy YARA rules targeting rdasrv process injection patterns and configure network intrusion detection systems to alert on DGA-based domain queries, using threat intelligence feeds from Trend Micro and Unit 42.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.