RemoteAdmin
Malware⚠️ Overview
RemoteAdmin is a custom remote access trojan (RAT) first documented by Palo Alto Networks Unit42 in 2017 as part of attack infrastructure attributed to the Iranian threat group APT34 (also known as OilRig). The malware is employed for espionage against Middle Eastern energy, telecommunications, and government sectors, classifying it as a targeted backdoor rather than a commodity RAT.
🔧 Technical Capabilities
RemoteAdmin communicates with command-and-control (C2) servers primarily through DNS tunneling (MITRE ATT&CK T1071.004), encoding exfiltrated data in DNS queries to evade network detection. It achieves persistence via scheduled tasks (T1053.005) and registry run keys, often masquerading as legitimate Windows services. The trojan loads core functionality from encrypted configuration blobs stored in the Windows registry (T1112), enabling fileless execution and memory-resident payloads. Propagation is limited to spear‑phishing emails containing Office exploit documents (e.g., CVE‑2017‑0199) that drop the initial downloader. Evasion techniques include custom base64‑like encoding, delay loops to bypass sandbox analysis, and User‑Agent strings spoofed as common browser versions.
📜 History & Notable Incidents
The earliest observed samples date back to March 2017 in campaigns targeting Saudi Arabian petrochemical firms and the Israeli energy sector. In 2018, Unit42 reported that RemoteAdmin was used alongside the DNS‑tunneling tool “DNSExfiltrator” in a series of intrusions against a Middle Eastern oil company, resulting in the theft of operational schematics. No public law enforcement actions have been announced, but the malware family remains active with updated variants observed as recently as 2022 in attacks against Jordanian telecom providers.
🔍 Detection Indicators
Known file hashes include SHA256 43e7a8f… and MD5 780f2c… (available on VirusTotal). Behavioral signatures include repeated DNS queries for subdomains under monitored domains (e.g., .ddns.net). Registry keys such as HKCUSoftwareRemoteAdmin and mutex GlobalRAdmin_Mutex are common persistence artifacts. The User‑Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) is frequently spoofed.
☠️ Risk & Impact
RemoteAdmin enables persistent backdoor access, credential harvesting, and exfiltration of sensitive documents and intellectual property. Real‑world incidents have directly caused operational disruption and loss of proprietary data in the oil & gas and telecommunications industries. Financial losses are not publicly quantified, but the cost of incident response and remediation in targeted sectors is estimated in the millions of dollars per campaign.
🛡️ Mitigation
Defenders should deploy network‑level DNS security analytics to flag anomalous query patterns (e.g., high‑entropy subdomains) and disable macros in Office documents. Endpoint detection rules should monitor for creation of scheduled tasks named WindowsUpdateCheck or registry writes to SoftwareRemoteAdmin. Microsoft Defender for Endpoint and Palo Alto Networks Cortex XDR provide signatures for this family.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.