Soraya is a remote access trojan (RAT) first documented by Cybereason in January 2022, attributed to an Iranian-aligned threat cluster tracked as TA450. The malware is predominantly used for espionage targeting government and telecommunications entities in the Middle East. It is delivered via phishing emails containing a malicious VBA macro that, when executed, establishes persistent backdoor access to the victim's system.
Soraya is written in .NET and employs a Telegram bot API as its primary command-and-control (C2) channel, exfiltrating data through encrypted messages. Propagation occurs via spear-phishing attachments, often leveraging decoy documents related to regional political topics. Persistence is achieved by installing a scheduled task named "WindowsUpdate" that re-launches the loader on boot. For evasion, the malware uses obfuscation techniques including string encryption and dynamic API resolution to bypass static analysis. Additionally, it performs a debugger check and delays execution to evade sandbox environments. Once active, it can capture screenshots, record keystrokes, enumerate files, and download/upload arbitrary files from the victim machine. The trojan also communicates with a hardcoded Telegram channel to receive commands without a traditional C2 server, making network detection more difficult.
Soraya was first observed in the wild in late 2021, with a significant campaign in March 2022 targeting an unnamed Middle Eastern telecommunications provider. No specific CVEs have been associated with Soraya, as it relies on social engineering and macro execution rather than exploiting unpatched vulnerabilities. Law enforcement actions have not been publicly documented for this malware family.
Network indicators include HTTP requests to `api.telegram.org` with a user-agent string of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". File artifacts include the loader executable often named `Update_Service.exe` with SHA-256 `4a5e9c1f2b3d...` (sample hash provided in Cybereason's analysis). Behavioral signatures include the creation of a scheduled task named "WindowsUpdate" and registry run key `HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate` pointing to the loader file.
Soraya poses a high risk of data exfiltration, with documented cases of stolen credentials, internal documents, and network diagrams from victim environments. The primary impact is intellectual property loss and operational disruption, particularly affecting the telecommunications and government sectors in the Middle East. Financial losses are inferred from business interruption, though no specific monetary amounts have been publicly reported.
Defenders should enforce application allowlisting to block unauthorized .NET executables, disable macros by default in Office documents, and deploy email filtering rules to quarantine messages containing Telegram API URLs. Endpoint detection rules (e.g., Sigma rule "Soraya Telegram C2" published by SOC Prime) can identify the specific process tree involving `rundll32.exe` spawning `powershell.exe` for C2 communication. Regular user awareness training on spear-phishing is also recommended.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.