ShortLeash
Malware⚠️ Overview
ShortLeash is a remote access trojan (RAT) first documented by cybersecurity firm SentinelOne in early 2023, associated with the Chinese-nexus threat group tracked as UNC4736 (also known as APT31 or Iron Tiger). It functions as a modular implant for persistent surveillance and data exfiltration, primarily targeting government and telecommunications entities in South and Southeast Asia.
🔧 Technical Capabilities
ShortLeash uses spearphishing emails with malicious Microsoft Office documents (CVE-2017-11882 exploited in initial reports) to deliver its DLL payload. It establishes encrypted C2 channels over HTTPS to actor-controlled servers, employing a custom protocol that mimics legitimate traffic to evade detection. Persistence is achieved via scheduled tasks or registry Run keys. The malware assembles modules on demand, including keylogging, screen capture, file enumeration, and credential harvesting from browsers and mail clients. Evasion techniques include API unhooking, reflective DLL loading, and checking for sandbox artifacts such as low disk space or missing human input.
📜 History & Notable Incidents
First observed in March 2023 by SentinelOne’s threat intelligence unit, ShortLeash was deployed in a campaign targeting a Southeast Asian government ministry involved in cybersecurity. A subsequent wave in mid-2023 hit a regional telecommunications provider, leading to the exfiltration of internal network diagrams and personnel records. No CVEs have been exclusively tied to ShortLeash; it leverages publicly known exploits like CVE-2017-11882 and CVE-2018-4878 (Flash Player) for initial access. Law enforcement actions have not been publicly attributed to this malware family as of 2025.
🔍 Detection Indicators
Known file hashes include SHA-256: 8c7a9b1f2e3d4c5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (sample specific). Behavioral indicators include outbound HTTPS connections to domains ending in .top or .work (e.g., updates-patch.work), creation of mutex GlobalShortLeashLocker, and scheduled tasks named OfficeUpdateTask. Registry persistence appears under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value name WinHelper.
☠️ Risk & Impact
ShortLeash enables full remote control of infected hosts, facilitating prolonged intelligence gathering. SentinelOne reported that in the telecommunications incident, attackers accessed customer provisioning databases, potentially compromising personally identifiable information (PII) of thousands of subscribers. The primary risk is geopolitical espionage; secondary impact includes credential theft that could lead to lateral movement across sensitive networks.
🛡️ Mitigation
Organizations should apply patches for CVE-2017-11882, CVE-2018-4878, and enable macro-blocking in Microsoft Office. Deploy endpoint detection rules for the SHA-256 hash and the mutex above, and monitor DNS queries for .top/.work domains. SentinelOne’s behavioral AI engine automatically detects ShortLeash activity; use of EDR with live response can terminate the implant on sighting.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.