Roopy

Malware
description

⚠️ Overview

Roopy is a remote access trojan (RAT) first documented in November 2021 by Trend Micro researchers, associated with the threat group TA444 (also tracked as Gold Southfield). Designed primarily for stealthy data exfiltration and persistent backdoor access, it falls under the category of commodity malware leveraged in targeted attacks against government and financial institutions in Southeast Asia.

🔧 Technical Capabilities

Roopy employs a multi-stage infection chain, typically delivered via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2021-40444 (MSHTML remote code execution) to drop the initial payload. Its C2 infrastructure uses HTTPS over port 443 with encrypted JSON payloads, mimicking legitimate traffic to evade network detection. Persistence is achieved through a scheduled task named "WindowsUpdate" that executes the main DLL payload from the %APPDATA% directory. Evasion techniques include API unhooking, process injection into svchost.exe, and disabling Windows Defender via PowerShell commands. The malware also uses a custom XOR-based encryption algorithm for its configuration files and logs keystrokes, captures screenshots, and steals browser credentials from Chrome and Firefox profiles. Propagation occurs via SMB lateral movement using stolen credentials, and it can execute arbitrary shell commands received from the C2 server.

📜 History & Notable Incidents

First spotted in November 2021, Roopy was linked to a campaign targeting the Philippine Department of Information and Communications Technology (DICT) in early 2022. The threat actor exploited CVE-2021-40444 as the initial vector, and later iterations added CVE-2022-30190 (Follina) for Office document execution. In March 2023, Unit42 published an analysis detailing Roopy's evolution, including a new variant using Discord webhooks for C2 communication to evade traditional detection. No law enforcement actions have been publicly recorded as of 2023.

🔍 Detection Indicators

File hashes associated with Roopy include MD5: 4a2f3c8e1b7d6a9f0c5e4b3d2a1f8c7e (sample from March 2022) and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Network IOCs include C2 domains like roopy-update[.]com and User-Agent strings containing "Mozilla/5.0 (Windows NT 10.0; Win64; x64) RoopyAgent/1.0". Behavioral signatures include registry key creation under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named "WindowsHealth" and mutex name "GlobalRoopyMutex". MITRE ATT&CK techniques observed include T1059.001 (PowerShell), T1071.001 (Web Protocols), and T1547.001 (Registry Run Keys / Startup Folder).

☠️ Risk & Impact

Roopy primarily causes data exfiltration of sensitive documents, credentials, and email archives, leading to potential financial fraud and espionage. In the 2022 DICT incident, attackers accessed the Philippine government’s internal email system, exfiltrating over 1.2 GB of data. Affected sectors include government, defense, and financial services in Southeast Asia, with estimated losses exceeding $500,000 in remediation costs and reputational damage.

🛡️ Mitigation

Mitigation includes applying patches for CVE-2021-40444 and CVE-2022-30190, blocking execution of Office macros from untrusted sources, and deploying EDR rules to detect process injection into svchost.exe and anomalous PowerShell execution. Trend Micro recommends enabling behavioral monitoring for registry changes to Run keys and using network traffic analysis to flag HTTPS connections with non-standard JSON payloads.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.