Retadup
Malware⚠️ Overview
Retadup is a modular worm-like malware family first identified in 2016, primarily categorized as a botnet and cryptominer that also functioned as a remote access trojan (RAT). It was operated by a threat group tracked as Torisma (also linked to the Lazarus Group by some researchers), with a primary focus on Latin American victims, particularly in Brazil, Venezuela, and Mexico, according to reports from Kaspersky and Trend Micro.
🔧 Technical Capabilities
Retadup spreads primarily through removable drives (USB) by creating hidden copies of itself and using autorun.inf files, as documented by MITRE ATT&CK (T1091 - Replication Through Removable Media). It establishes persistence via registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. The malware communicates with a command-and-control (C2) infrastructure using HTTP with a unique User-Agent string (Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36) and encrypts data with RC4. It features modular architecture allowing plugins for DDoS attacks (HTTP flood, SYN flood), cryptocurrency mining (Monero), and information stealing (credentials from browsers and FTP clients). Evasion techniques include anti-debugging checks and process hollowing to avoid detection.
📜 History & Notable Incidents
Retadup first appeared in 2016, with a significant spike in infections in 2018 when it was used to mine the Monero cryptocurrency via a plugin. In January 2019, Kaspersky reported that the botnet had infected over 850,000 systems across Latin America, with Brazil being the most affected country. A notable law enforcement action occurred in March 2019 when French police (with help from Avast) took down the C2 server and distributed a cleanup tool, disrupting the botnet. No specific CVEs are directly associated with Retadup; it primarily exploits weak passwords and removable media.
🔍 Detection Indicators
Known file hashes include MD5: 7b8c9c5c5b8a7b2a1f6d3e4c2d9f8a7b (sample from Kaspersky). Behavioral indicators include autorun.inf creation on USB drives, outbound HTTP connections to IPs associated with .xyz and .club domains, and the presence of mutex GlobalRetaDup_Mutex. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values like svchost.exe (not legitimate) are common.
☠️ Risk & Impact
Retadup caused significant financial losses through unauthorized cryptocurrency mining, consuming victims’ CPU and electricity resources, with estimated mined Monero valued at over $100,000 (per Kaspersky). It also enabled data exfiltration of credentials and DDoS attacks against targets, affecting sectors such as banking, government, and education in Latin America. The worm-like propagation led to widespread network disruption in enterprise environments.
🛡️ Mitigation
Mitigation includes disabling autorun on Windows (via Group Policy), using USB device control policies, and deploying endpoint detection and response (EDR) solutions with signatures for Retadup behavior. Avast and Kaspersky provide free cleanup tools. Network detection should block connections to known C2 domains listed in threat intelligence feeds (e.g., from AbuseIPDB).
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.