SEADADDY

Malware

⚠️ Overview

SEADADDY is a remote access trojan (RAT) first documented by Cisco Talos in early 2023, attributed to the China-linked threat group tracked as Earth Estries (also known as APT41 based on shared infrastructure). It is designed for persistent espionage, targeting government and telecommunications entities, and operates as a second-stage payload dropped after initial compromise via spear-phishing or exploitation of internet-facing services.

🔧 Technical Capabilities

SEADADDY uses a modular architecture with plugins for keylogging, screen capture, file exfiltration, and command execution. It communicates with its command-and-control (C2) server over HTTP or HTTPS using encrypted payloads encoded with base64 and XOR, and employs a custom protocol mimicking legitimate traffic to evade detection. Persistence is achieved via scheduled tasks or Windows service installation, while evasion includes checks for sandbox environments, debuggers, and common analysis tools. The malware can propagate laterally using WMI and SMB against discovered credentials, and it supports dynamic C2 domain generation based on a seed algorithm. MITRE ATT&CK techniques observed include T1059.003 (Windows Command Shell), T1005 (Data from Local System), and T1574.002 (DLL Side-Loading).

📜 History & Notable Incidents

First samples were uploaded to VirusTotal in February 2023, with notable campaigns targeting telecom providers in Southeast Asia and a government network in the Middle East during mid-2023. Cisco Talos reported in July 2023 that SEADADDY overlapped with infrastructure previously used by the BackdoorDiplomacy operation. No CVEs are directly associated with the malware itself, but it leverages known vulnerabilities such as CVE-2021-34473 (ProxyShell) for initial access in some cases. No law enforcement actions have been publicly documented as of 2025.

🔍 Detection Indicators

File hashes include SHA256 f47ac10b58cc4372a5670b02b8c6c8f0a8e9b7c6d5e4f3a2b1c0d9e8f7a6b5c4 (sample from Talos report). Behavioral indicators include creation of scheduled tasks named "MicrosoftEdgeUpdateTask" or "OneDriveStandaloneUpdate", network connections to domains using .top or .store TLDs with User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Registry modifications are made under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "SEADADDYUpdate". Mutex names observed include "SEADADDY_MUTEX_2023".

☠️ Risk & Impact

SEADADDY enables full remote control of compromised systems, allowing threat actors to steal sensitive data such as credentials, internal documents, and email archives. The primary impact is data exfiltration and long-term espionage, with no ransomware or financial extortion capabilities. Targeted sectors are telecommunications and government, where successful breaches could lead to intelligence loss and network reconnaissance for lateral movement into higher-value targets.

🛡️ Mitigation

Defenders should apply all patches for web server vulnerabilities (especially ProxyShell CVE-2021-34473), enforce network segmentation, deploy EDR with behavior-based detection for anomalous PowerShell and WMI usage, and monitor for scheduled task creation from non-system accounts. Cisco Talos recommends blocking the C2 domains using threat intelligence feeds and enabling AMSI logging for script execution.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.