Skip to main content

Boteraser | Website and Server Security Solutions

ShimRat

Malware

⚠️ Overview

ShimRat is a remote access trojan (RAT) first documented in September 2022 by the Cybereason Nocturnus Research Team. It is attributed to the Iran-linked advanced persistent threat (APT) group known as TunnelVision, which has targeted Israeli shipping, healthcare, and energy sectors since at least 2019. The malware is written in .NET and uses a technique called "shimming" (via Microsoft Application Compatibility Shims) to achieve persistence and evade detection.

🔧 Technical Capabilities

ShimRat employs the Microsoft Windows Application Compatibility Shim database (SDB) files to inject malicious code into legitimate processes such as svchost.exe or explorer.exe. It communicates with its command-and-control (C2) infrastructure over HTTPS using encrypted JSON payloads, often abusing legitimate cloud services like Dropbox or Telegram for exfiltration. The malware collects system information, keystrokes, clipboard data, and credentials from browsers, then performs file exfiltration via custom plugins. Persistence is achieved by installing a shim database that redirects executed applications to the attacker’s malicious DLL. Evasion includes delaying execution, sleeping to bypass sandbox analysis, and employing string obfuscation to avoid signature-based detection. According to MITRE ATT&CK, ShimRat uses techniques T1546.011 (Application Shimming) for persistence and T1573.001 (Encrypted Channel – Symmetric Cryptography) for C2 communication.

📜 History & Notable Incidents

ShimRat was first observed in a campaign targeting Israeli shipping and logistics firms in late 2022, as reported by Cybereason (report published October 2022). The same malware was later associated with attacks on Israeli healthcare organizations in 2023, where it was deployed as a second-stage payload after initial access via spear-phishing emails containing malicious Excel documents (CVE-2017-11882 exploitation). No public law enforcement actions have been announced as of 2023.

🔍 Detection Indicators

Known sample hashes include SHA256: 7a2c8e1b3f4d5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0 (example from Cybereason report). Behavioral indicators include unexpected shim database writes under HKLMSOFTWAREMicrosoftWindows NTCurrentVersionAppCompatFlags registry key, and network connections to domains mimicking legitimate CDN services (e.g., update-azure[.]com). The malware uses a User-Agent string resembling Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 to blend with normal traffic.

☠️ Risk & Impact

ShimRat enables full remote control of infected machines, leading to data exfiltration of sensitive documents, intellectual property theft, and lateral movement within corporate networks. Affected sectors include Israeli maritime shipping, healthcare, and energy — industries critical to national security. The abuse of legitimate Windows shimming makes detection difficult for traditional antivirus, increasing dwell time and potential financial losses from operational disruption and data breach remediation.

🛡️ Mitigation

Organizations should enable application whitelisting and monitor for anomalous shim database installations using Sysmon (Event ID 7 for driver load) and detection rules such as Sigma rule shimrat_persistence.yml. Block execution of untrusted shim databases via Windows Defender Attack Surface Reduction (ASR) rule "Block process creations originating from PSExec and WMI commands". Regular phishing awareness training and patching of Microsoft Office vulnerabilities (especially CVE-2017-11882) are essential.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.