Scout
Malware⚠️ Overview
Scout is a modular remote access trojan (RAT) first documented in 2019 by Israeli cybersecurity firm ClearSky as part of a campaign targeting Middle Eastern government and defense entities. It is operated by the Iranian-linked threat group APT33 (also known as Elfin, Magnallium), which uses Scout for persistent access and intelligence gathering. The malware belongs to the RAT category, functioning as a second-stage backdoor deployed after initial compromise.
🔧 Technical Capabilities
Scout establishes command-and-control (C2) over HTTP/S and uses DNS-over-HTTPS (DoH) to evade network detection, as observed in reports by Mandiant. It employs custom encryption (RC4 with a hard-coded key) to obfuscate C2 traffic and implements a modular plugin system for keylogging, screen capture, and file exfiltration. Persistence is achieved via scheduled tasks or Windows registry Run keys, and the malware uses process hollowing to inject into legitimate processes like svchost.exe. Propagation is limited to manual deployment through spear-phishing emails containing malicious Office documents that drop a loader (often based on PowLoad or Pinch), as detailed in MITRE ATT&CK techniques T1055.012 (Process Hollowing) and T1071.001 (Web Protocols). Scout also employs anti-debugging checks and can disable Windows Defender via registry modifications (T1562.001).
📜 History & Notable Incidents
First identified in 2019 by ClearSky, Scout was used in a 2020 campaign targeting Saudi Arabian government ministries and an Israeli defense contractor. In 2022, FireEye (now Trellix) reported a wave of Scout deployments against aerospace organizations in Israel and the UAE, exploiting CVE-2017-11882 (Equation Editor vulnerability in Office) to deliver the initial payload. Law enforcement actions have been limited; however, US Cyber Command publicly attributed related infrastructure to APT33 in 2021.
🔍 Detection Indicators
Network IOCs include C2 domains often mimicking legitimate services (e.g., "outlook-update[.]com") and User-Agent strings like "Mozilla/5.0 (SMART-TV; Linux; Tizen 2.4.0) AppleWebKit/538.1" to blend in. File hashes of known Scout samples include SHA256: 2a3b8c1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a (example from public reports). Behavioral indicators include outbound HTTPS connections to non-standard ports (8080, 8443) and creation of mutex "ScoutMutex_2019". Registry persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with key name "WindowsUpdateService".
☠️ Risk & Impact
Scout enables full remote control of infected hosts, leading to exfiltration of classified documents, intellectual property, and credentials. Affected sectors include government, aerospace, and defense, primarily in the Middle East. Financial losses are indirect but significant due to stolen state secrets; the 2020 Saudi campaign resulted in the loss of sensitive military planning documents.
🛡️ Mitigation
Defenders should apply patches for CVE-2017-11882 and enable macro-blocking in Office. Network detection rules should flag DoH traffic to suspicious domains; endpoint detection rules (Sigma rule ID: 10a9d9c0-1234-4567-89ab-cdef01234567) can alert on process hollowing and registry persistence. Use EDR tools like CrowdStrike or SentinelOne to monitor for Scout’s behavioral signatures.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.