SoWaT is a modular backdoor malware documented by Trend Micro in August 2023 as part of the Earth Lusca advanced persistent threat (APT) group's toolset, categorized as a remote access trojan (RAT) used for espionage. It was first observed in active campaigns targeting government and diplomatic entities across Asia-Pacific, with the group believed to operate from China.
SoWaT propagates through spear-phishing emails leveraging CVE-2021-1732, a Windows Win32k elevation of privilege vulnerability. It uses DLL side-loading to inject its payload into legitimate processes like svchost.exe. The malware communicates with its command-and-control (C2) server via HTTP with RC4-encrypted payloads, using a custom header field "X-SoWaT: v1". It establishes persistence through scheduled tasks and adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include API hooking of EtwEventWrite and NtTraceEvent to disable ETW, and it can load plugins for keylogging, screen capture, and file exfiltration. According to Trend Micro, SoWaT also searches for and exfiltrates files with specific extensions like .doc, .pdf, and .xls.
Earth Lusca, active since 2019, deployed SoWaT alongside Cobalt Strike and Bifrost in campaigns from at least 2022. Notable incidents include targeting of Taiwanese government agencies and Philippine political think tanks. The malware's public analysis by Trend Micro linked it to the group's operational infrastructure hosted on compromised WordPress sites. No law enforcement actions have been reported against SoWaT specifically.
Known file hashes for SoWaT samples have been published by Trend Micro. Behavioral indicators include creation of mutex "GlobalSoWaT_Mutex" and use of User-Agent "Mozilla/5.0 (Windows NT 6.1; Win64; x64) SoWaTClient". Network IOCs include HTTP POST to /api/upload with encrypted data and C2 domains resembling legitimate sites. Registry keys under Run for persistence and scheduled task names "SoWaTUpdate" are reported.
SoWaT enables full remote control, leading to data exfiltration of sensitive documents, credentials, and intellectual property. Impacted sectors include government, think tanks, and NGOs in Taiwan, the Philippines, and Vietnam. Financial losses are primarily indirect through espionage, though remediation costs are significant.
Defenders should apply patches for CVE-2021-1732, implement email security to block spear-phishing, and use EDR solutions with YARA rules detecting SoWaT's DLL side-loading and network signatures. Trend Micro's report provides specific detection rules and indicators for hunting.
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.