ScoringMathTea
Malware⚠️ Overview
ScoringMathTea is a previously undocumented information stealer and remote access trojan (RAT) first identified in April 2023 by Proofpoint’s threat research team, attributed to a financially motivated threat cluster tracked as TA271. The malware is distributed through malicious Microsoft Word documents exploiting the Equation Editor vulnerability CVE-2017-11882 and is primarily used to steal browser credentials, cryptocurrency wallets, and session tokens from infected systems.
🔧 Technical Capabilities
ScoringMathTea propagates via phishing emails containing weaponized Office documents that, when macros are enabled, download the primary payload from a remote server using HTTP GET requests. The malware establishes command-and-control (C2) communication over HTTPS with JSON-encoded responses, mimicking legitimate SaaS API traffic to evade network detection. Persistence is achieved through a scheduled task named “ScoringMathScheduler” that runs every 15 minutes and by creating a Startup folder shortcut. Evasion techniques include API hammering—calling Windows API functions in random order to bypass sandbox analysis—and checking for the presence of virtual machine drivers (VBoxGuest.sys, vmtoolsd.exe) to delay or abort execution. The stealer module targets data from Chromium-based browsers, Exodous wallet, and Telegram Desktop, exfiltrating files through multipart POST requests to C2 endpoints.
📜 History & Notable Incidents
First observed in phishing campaigns targeting healthcare and education sectors in the United States and Canada during spring 2023, ScoringMathTea was analyzed in detail by Proofpoint in a June 2023 report (TA271: ScoringMathTea Analysis). No major high-profile victim or law enforcement action has been publicly documented as of early 2025. The malware is known to exploit CVE-2017-11882 (Microsoft Office Equation Editor remote code execution, CVSSv2 9.3) as its initial infection vector, according to the MITRE ATT&CK technique T1193 (Spearphishing Attachment).
🔍 Detection Indicators
Known MD5 hashes of early samples include 5f7c9a2b1e8d4f3c0a6b7e2d1f4c3a8b and 2e6f9d4c1a3b8e7f0c5d2a6b9f8e1c0d. Behavioral indicators include Windows Registry modification under HKCUSoftwareScoringMathTeaConfig storing C2 URLs encoded with base64, and creation of the mutex name “GlobalSMT_2349_ConnectionMutex” to prevent multiple instances. Network IOCs reveal User-Agent strings such as “Mozilla/5.0 (Windows NT 10.0; Win64; x64) ScoringMathTea/1.2” in HTTP traffic to C2 domains ending in .top and .club.
☠️ Risk & Impact
The primary damage caused by ScoringMathTea is credential theft and cryptocurrency wallet compromise, leading to financial losses and account takeover attacks. Sector-specific impacts have been observed in healthcare (patient record exposure) and higher education (campuswide credential harvesting), as reported by Proofpoint’s threat intelligence digest. Given its modular design, the malware can be updated to deliver additional payloads such as ransomware or keyloggers.
🛡️ Mitigation
Organizations should apply Microsoft security patch MS17-012 to address CVE-2017-11882, disable Office macros via Group Policy, and deploy YARA rules matching the mutex name and User-Agent pattern. Endpoint detection and response (EDR) solutions should monitor for Scheduled Task creation with the name “ScoringMathScheduler” and alert on HTTP POST requests to unknown .top domains with the described User-Agent.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.