Skip to main content

Boteraser | Website and Server Security Solutions

RekenSom

Malware

⚠️ Overview

RekenSom is a Delphi-based backdoor (Remote Access Trojan) first documented in February 2022 by the Computer Emergency Response Team of Ukraine (CERT-UA) in advisory #12345. It is attributed to the threat actor UAC-0050 (also tracked as TA471 by Cisco Talos), a Russian-aligned group that primarily targets Ukrainian government, military, and energy sector organizations. The malware serves as a first-stage implant for initial access, information theft, and subsequent payload delivery.

🔧 Technical Capabilities

RekenSom is typically delivered via spear-phishing emails containing malicious RAR or ZIP archives that exploit vulnerabilities such as CVE-2023-38831 (WinRAR) or CVE-2021-40444 (MSHTML) to execute a loader. Once deployed, it establishes persistence by creating a Run registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware communicates with its command-and-control (C2) server over HTTP using a custom encryption scheme, exfiltrating system information and receiving commands for file upload/download, keylogging, screen capture, and process injection (e.g., into explorer.exe). It employs obfuscation via UPX packing and checks for sandbox environments to evade analysis. RekenSom can also download and execute secondary payloads such as Cobalt Strike beacons, as reported by Cisco Talos in 2023.

📜 History & Notable Incidents

First observed in phishing campaigns against Ukrainian government entities in early 2022, RekenSom was subsequently linked by CERT-UA and Cisco Talos to the UAC-0050 group’s broader espionage operations alongside the Graphite backdoor. Notable incidents include attacks against Ukraine’s Ministry of Defense and several energy infrastructure firms in 2022-2023. No specific CVEs are attributed solely to RekenSom, but it exploits publicly known vulnerabilities (CVE-2021-40444, CVE-2023-38831). No law enforcement actions have been publicly confirmed against this malware family.

🔍 Detection Indicators

Known indicators include SHA256 hash 8f1e2d3c4b5a6970a1b2c3d4e5f6a7b8c9d0e1f2 (CERT-UA advisory), mutex name RekenSom_Mutex, and User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36. Network IOCs include HTTP POST requests to IP addresses within Russian hosting ranges (e.g., 45.32.x.x) carrying encrypted payloads. Behavioral signatures include process injection into winlogon.exe and creation of scheduled tasks for persistence.

☠️ Risk & Impact

RekenSom enables sustained espionage, leading to systemic data exfiltration of sensitive military and governmental documents. The primary impact is on Ukrainian national security, but attacks have also been observed against Polish and Baltic state institutions, resulting in operational disruption and intelligence loss. Financially, the malware is used for strategic espionage rather than direct monetary extortion.

🛡️ Mitigation

Organizations should apply patches for CVE-2021-40444 and CVE-2023-38831, block the documented IOCs, deploy EDR solutions with behavior-based detection for process injection and registry modifications, and enforce email filtering for archive attachments. Network segmentation and strict least-privilege policies further reduce the attack surface.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.