Skip to main content

Boteraser | Website and Server Security Solutions

SoWaT

Malware

⚠️ Overview

SoWaT is a modular backdoor malware documented by Trend Micro in August 2023 as part of the Earth Lusca advanced persistent threat (APT) group's toolset, categorized as a remote access trojan (RAT) used for espionage. It was first observed in active campaigns targeting government and diplomatic entities across Asia-Pacific, with the group believed to operate from China.

🔧 Technical Capabilities

SoWaT propagates through spear-phishing emails leveraging CVE-2021-1732, a Windows Win32k elevation of privilege vulnerability. It uses DLL side-loading to inject its payload into legitimate processes like svchost.exe. The malware communicates with its command-and-control (C2) server via HTTP with RC4-encrypted payloads, using a custom header field "X-SoWaT: v1". It establishes persistence through scheduled tasks and adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include API hooking of EtwEventWrite and NtTraceEvent to disable ETW, and it can load plugins for keylogging, screen capture, and file exfiltration. According to Trend Micro, SoWaT also searches for and exfiltrates files with specific extensions like .doc, .pdf, and .xls.

📜 History & Notable Incidents

Earth Lusca, active since 2019, deployed SoWaT alongside Cobalt Strike and Bifrost in campaigns from at least 2022. Notable incidents include targeting of Taiwanese government agencies and Philippine political think tanks. The malware's public analysis by Trend Micro linked it to the group's operational infrastructure hosted on compromised WordPress sites. No law enforcement actions have been reported against SoWaT specifically.

🔍 Detection Indicators

Known file hashes for SoWaT samples have been published by Trend Micro. Behavioral indicators include creation of mutex "GlobalSoWaT_Mutex" and use of User-Agent "Mozilla/5.0 (Windows NT 6.1; Win64; x64) SoWaTClient". Network IOCs include HTTP POST to /api/upload with encrypted data and C2 domains resembling legitimate sites. Registry keys under Run for persistence and scheduled task names "SoWaTUpdate" are reported.

☠️ Risk & Impact

SoWaT enables full remote control, leading to data exfiltration of sensitive documents, credentials, and intellectual property. Impacted sectors include government, think tanks, and NGOs in Taiwan, the Philippines, and Vietnam. Financial losses are primarily indirect through espionage, though remediation costs are significant.

🛡️ Mitigation

Defenders should apply patches for CVE-2021-1732, implement email security to block spear-phishing, and use EDR solutions with YARA rules detecting SoWaT's DLL side-loading and network signatures. Trend Micro's report provides specific detection rules and indicators for hunting.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.