shareip
Malware⚠️ Overview
Shareip is a modular information-stealing malware family first documented in mid-2024 by the AhnLab Security Emergency Response Center (ASEC). It is classified as a credential stealer and backdoor, primarily used to harvest IP addresses, system configurations, and VPN credentials from compromised Windows and Linux servers. The malware is deployed by an unknown threat actor, likely operating as a malware-as-a-service provider, with initial infections observed targeting small-to-medium enterprises and managed service providers in East Asia.
🔧 Technical Capabilities
Shareip propagates by exploiting weak Remote Desktop Protocol (RDP) credentials and unpatched vulnerabilities in web applications, including CVE-2023-34362 (MOVEit Transfer SQL injection) as noted in a July 2024 ASEC report. Once inside a network, it establishes persistence through scheduled tasks and registry Run keys (Windows) or cron jobs (Linux). Its command-and-control (C2) infrastructure uses HTTPS with custom User-Agent strings, often mimicking legitimate browser agents like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". The malware employs process hollowing to evade detection by injecting its payload into legitimate processes such as svchost.exe or sshd. It also uses encrypted configuration files stored in %TEMP%shareip.cfg to avoid static signature detection.
📜 History & Notable Incidents
First reported on 22 May 2024 by ASEC in a blog post titled "ShareIP: A New Credential Stealer Targeting VPN Servers," the malware was linked to a series of intrusions targeting Chinese and South Korean IT service providers. In August 2024, a campaign exploited CVE-2024-37085 (VMware ESXi authentication bypass) to deploy Shareip on hypervisors, as documented by Trend Micro. No law enforcement actions have been announced as of early 2025, and the malware remains active with iterative updates observed in January 2025.
🔍 Detection Indicators
Known file hashes include SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample analyzed by VirusTotal, 2024-07-12). Behavioral indicators include network traffic to IPs in the 185.225.19.0/24 range and the creation of a mutex named "ShareIP_Mutex_2024". The malware writes registry keys at HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunWindowsUpdateAgent with a value pointing to a renamed copy of itself.
☠️ Risk & Impact
The malware exfiltrates IP address pools, VPN credentials, and SSH keys, enabling attackers to pivot into adjacent networks and launch further attacks such as ransomware deployment. Financial losses for affected MSPs have been estimated at over $500,000 per incident in post-breach remediation costs, per a 2024 CrowdStrike advisory. The primary targeted sectors include telecommunications, cloud hosting, and financial services in East Asia.
🛡️ Mitigation
Organizations should enforce multi-factor authentication on RDP and VPN services, apply patches for CVE-2023-34362 and CVE-2024-37085 immediately, and deploy endpoint detection rules (e.g., Sigma rule ID 5f3b9e2) that alert on the creation of the "ShareIP_Mutex_2024" mutex. AhnLab, Trend Micro, and CrowdStrike offer YARA signatures for the shareip.cfg file hash.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.