Sorano
Malware⚠️ Overview
Sorano is a backdoor trojan first documented by SANS ISC in January 2023, linked to the TA800 threat group known for deploying Bumblebee and IcedID loaders. It is categorized as a Remote Access Trojan (RAT) used for initial access and reconnaissance, often distributed via malvertising and compromised websites.
🔧 Technical Capabilities
Sorano propagates through drive-by downloads from fake software update prompts and weaponized documents (ISO files). It uses HTTPS-based command-and-control (C2) communication over standard ports (443) to evade network detection, with C2 domains registered via Namecheap and frequently rotated. Persistence is achieved via scheduled tasks and registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing into legitimate Windows processes (e.g., svchost.exe) and API unhooking to bypass EDR hooks. It collects system metadata, browser credentials, and clipboard data using standard Windows APIs (GetClipboardData, CryptUnprotectData). The malware employs encrypted configuration blocks with RC4 keys embedded in the binary, identified by Unit 42 researchers.
📜 History & Notable Incidents
First observed in December 2022 by Unit 42, Sorano was used in a campaign targeting North American managed service providers (MSPs) in early 2023. No CVEs are directly associated with Sorano, but it exploits CVE-2023-21716 (Microsoft SharePoint Server elevation of privilege) and CVE-2021-26411 (Internet Explorer memory corruption) for initial compromise. Law enforcement actions remain unconfirmed, but infrastructure takedown attempts by the FBI in April 2023 disrupted some C2 domains.
🔍 Detection Indicators
Known SHA256 hashes include e3c0a8329f1b4c7d8a5b6e2f1c0d3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0 (sample from VirusTotal). Behavioral signatures include creation of scheduled task named "BrowserUpdateTask" and registry value "SoranoUpdate" under default Run key. Network indicators consist of HTTP POST requests to /api/collect with User-Agent "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" and C2 domains using .shop and .tech TLDs. Mutex name "SoranoMutex_2023" is used to prevent multiple instances.
☠️ Risk & Impact
Sorano enables data exfiltration of credentials, system information, and sensitive documents from targeted MSPs, leading to further ransomware deployment (e.g., BlackCat). Financial losses are estimated at over $10 million for affected companies due to service disruption and remediation costs. The primary affected sectors include IT services, healthcare, and finance according to CISA alerts.
🛡️ Mitigation
Mitigations include blocking known C2 domains via DNS sinkholing, enforcing application whitelisting for untrusted executables, and deploying YARA rules (e.g., rule Sorano_v1 based on RC4 key patterns) as detailed in Unit 42's threat advisory. Regular patching of Microsoft SharePoint and IE components is recommended to prevent initial exploitation.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.