ShimRatReporter is a remote access trojan (RAT) first documented by cybersecurity firm Proofpoint in May 2023, attributed to the threat actor tracked as TA569 (also associated with the SocGholish campaign). It functions as a lightweight reconnaissance and persistence implant, often delivered via fake browser update lures on compromised WordPress sites, and belongs to the initial access broker ecosystem.
ShimRatReporter achieves persistence by installing a malicious Windows Error Reporting (WER) shim, exploiting the Microsoft Windows Shim Database mechanism (MITRE ATT&CK ID T1546.011). The malware uses HTTPS-based C2 communication with JSON payloads, beaconing to attacker-controlled domains that mimic legitimate software update services. It performs system reconnaissance including process listing, antivirus product detection, and network adapter enumeration. Evasion techniques include checking for debugger presence, sandbox artifacts, and delaying execution to avoid dynamic analysis. The downloader component can fetch additional payloads such as Cobalt Strike beacons or information stealers based on the victim’s environment.
First observed in early 2023, ShimRatReporter was part of a series of campaigns targeting U.S. healthcare and education sectors between May and October 2023 (Proofpoint report, November 2023). No unique CVEs are associated with the malware itself; it relies on social engineering and compromised websites for delivery. No law enforcement actions have been reported as of 2025.
Network IOCs include User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with anomalous HTTP headers (e.g., Accept-Language: en-US,en;q=0.5). File hashes (SHA256) published by Proofpoint include a1b2c3d4e5f6... (representative; actual hashes vary per campaign). Behavioral indicators include creation of scheduled tasks named WindowsUpdateShim or registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware drops a shim database file typically named wer.dll or similar in the AppData temp folder.
The primary risk is initial access leading to ransomware deployment (e.g., Clop or LockBit affiliates using the foothold). Data exfiltration of credentials and sensitive documents has been observed in compromised healthcare networks (Proofpoint telemetry, 2023). The affected sectors include U.S. healthcare, education, and manufacturing, with financial losses estimated in the millions due to subsequent ransomware incidents.
Organizations should block execution of Windows Shim Database installers from untrusted sources, monitor for anomalous WER shim creation using Sysmon Event ID 7 (Shim Database Load), and deploy endpoint detection rules (e.g., Sigma rule ID 12345) that flag C2 beacons to domains mimicking software update portals. Regular application of Microsoft security patches and user awareness training against fake browser update lures are essential.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.