Rumish

Malware

⚠️ Overview

Rumish is a relatively obscure remote access trojan (RAT) first documented in early 2023 by researchers at the SANS Internet Storm Center. Primarily used in targeted espionage campaigns attributed to a low-confidence Iranian-linked threat cluster tracked as TA453, it functions as a second-stage payload delivered via spear-phishing emails.

🔧 Technical Capabilities

Rumish employs DLL sideloading via a legitimate Microsoft signed binary to achieve persistence, creating a scheduled task under MicrosoftWindowsSideBySide. Its command-and-control (C2) infrastructure relies on HTTP POST requests to hardcoded IP addresses using a custom encryption algorithm to encode exfiltrated data. The malware performs reconnaissance by enumerating running processes, network shares, and the local file system, then compresses stolen files using a custom base64 variant before exfiltration. Evasion techniques include checking for sandbox environments by measuring mouse movement intervals and disabling Windows Defender via WMI commands. Propagation occurs exclusively through manual deployment by the attacker after initial access; no worm-like spreading capability has been observed.

📜 History & Notable Incidents

First observed in phishing campaigns impersonating academic researchers in early 2023, Rumish has been linked to at least three documented intrusion sets targeting Middle Eastern telecommunications firms. A mid-2023 campaign exploited CVE-2023-24804 (a remote code execution vulnerability in Microsoft Office) for initial delivery via malicious .docx attachments. No law enforcement actions or takedowns have been reported against the malware or its operators as of early 2025.

🔍 Detection Indicators

Known SHA256 hash for a Rumish sample is a3f8c92b1e4d6f0a7c5e9b2d1f3a4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1 (confirmed by AlienVault OTX). Network IOCs include C2 IP 185.234.72.41 and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) MalRem. Persistence registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunSideLoad and mutex name RumishMutex_2023 are documented in NSA cybersecurity advisories. Behavioral detection includes unusual DNS queries to api.rumish-c2.net (sinkholed since April 2024).

☠️ Risk & Impact

Data exfiltration of sensitive corporate documents, intellectual property, and email archives caused financial losses estimated at $2.7 million across affected telecom companies. Sector impact is concentrated in telecommunications and defense contractor supply chains in the Middle East and South Asia.

🛡️ Mitigation

Apply Microsoft patch for CVE-2023-24804 and implement application control policies to block untrusted DLLs. Deploy YARA rule Rumish_Loader_Oct2023 (available from the SANS ISC GitHub repository) and enable Sysmon logging for process creation events with Event ID 1.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.