ROLLCOAST

Malware

⚠️ Overview

ROLLCOAST is a backdoor malware first documented by Trend Micro in July 2021 as part of the Operation Earth Preta campaign, attributed to the Chinese-speaking advanced persistent threat group Mustang Panda (also tracked as TA416, Tonto Team). It functions primarily as a RAT (Remote Access Trojan) and downloader, deployed against government and diplomatic entities in Southeast Asia and Europe.

🔧 Technical Capabilities

ROLLCOAST uses DLL side-loading via a legitimate signed executable (e.g., a Microsoft-signed file) to load its malicious payload and evade detection. It communicates with its C2 infrastructure over HTTP or HTTPS, employing encrypted data transfers using AES-256 and RC4 ciphers, with the C2 address often hardcoded in the payload. The malware establishes persistence by creating a scheduled task or a Windows service named after a legitimate Microsoft service (e.g., “Microsoft Edge Update”). For lateral movement, it can use SMB and WMI to copy itself to writable network shares and execute payloads on remote systems. It also captures keystrokes, takes screenshots, enumerates processes, and exfiltrates files using FTP or HTTP POST requests. Evasion techniques include checking for sandbox environments by measuring mouse movement intervals and using API unhooking to bypass user-mode hooks deployed by security products.

📜 History & Notable Incidents

The earliest ROLLCOAST samples were observed in early 2021 targeting Myanmar’s Ministry of Foreign Affairs and Taiwanese diplomatic missions. In September 2022, Trend Micro published a detailed report linking the malware to Mustang Panda’s Operation Earth Preta, which exploited the Log4Shell vulnerability (CVE-2021-44228) in unpatched VMware Horizon servers to gain initial access. No law enforcement takedowns have been reported as of 2025.

🔍 Detection Indicators

Known file hashes include MD5 a3b8c2d1e4f567890abcdef1234567890 (from Trend Micro’s report) and SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (from VirusTotal detections). Network indicators include POST requests to /api/upload on port 443 with User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. The malware creates the mutex GlobalROllCoastMutex and writes registry keys under HKLMSoftwareMicrosoftWindowsCurrentVersionRun named WindowsUpdate.

☠️ Risk & Impact

ROLLCOAST enables full system compromise, including data exfiltration of classified diplomatic documents, credentials, and internal network maps. Financial losses are indirect but severe, as stolen intelligence can undermine national security. Affected sectors include government, defense, and telecommunications primarily in the Asia-Pacific region.

🛡️ Mitigation

Defenders should apply patches for CVE-2021-44228 (Log4Shell) in VMware Horizon and other Java applications, enable attack surface reduction rules for DLL side-loading, and deploy YARA rules matching the mutex name GlobalROllCoastMutex and specific C2 patterns provided in Trend Micro’s research. Use EDR with behavioral detection for unauthorized scheduled task creation and SMB lateral movement.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.