ROAMINGHOUSE

Malware

⚠️ Overview

RoamingHouse is a backdoor malware family first observed in 2021, attributed to the Chinese state-sponsored threat group Roaming Tiger (also tracked as TA427). It is categorized as a remote access trojan (RAT) used for espionage and data exfiltration, as documented by MITRE ATT&CK under software ID S1077.

🔧 Technical Capabilities

RoamingHouse is written in C++ and communicates with its command-and-control (C2) server via HTTP using encrypted payloads encoded with Base64. It achieves persistence by creating a scheduled task or adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware employs evasion techniques including checking for virtual machine environments (e.g., VMware, VirtualBox) and using sleep timers to avoid sandbox detection. Propagation is typically via spear-phishing emails with malicious document attachments. The C2 infrastructure uses hardcoded IP addresses or domains with HTTP POST requests containing encrypted data. MITRE ATT&CK notes use of obfuscated files and information.

📜 History & Notable Incidents

RoamingHouse first appeared in early 2021, with campaigns targeting government and telecommunications organizations in Southeast Asia, particularly in Myanmar and Thailand, according to Palo Alto Networks Unit 42 reports. No specific high-profile victims have been publicly named, but the malware is associated with the Roaming Tiger group which has been active in regional espionage. No known CVEs are exploited; instead, the group relies on social engineering and custom payloads.

🔍 Detection Indicators

Known behavioral indicators include the presence of a mutex named RoamingHouse_Mutex and registry persistence under Run keys. Network indicators include HTTP POST requests to suspicious domains with a User-Agent string of Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36. File hashes are not widely published but the malware often masquerades as benign executables like svchost.exe. MITRE ATT&CK also lists file names like version.dll as potential indicators.

☠️ Risk & Impact

The primary impact is data exfiltration and espionage, targeting sensitive government and telecom infrastructure. Financial losses are indirect, stemming from breach costs and loss of intellectual property. The affected sectors are predominantly government, defense, and telecommunications in Asia, as reported by Trend Micro and CrowdStrike threat assessments.

🛡️ Mitigation

Defenders should implement network monitoring for anomalous HTTP traffic, deploy endpoint detection rules for the known mutex and registry persistence, and conduct phishing awareness training. MITRE ATT&CK (S1077) provides behavioral detection recommendations; organizations should also apply principle of least privilege and use email filtering to block malicious attachments.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.