SpaceCow

Malware

⚠️ Overview

SpaceCow is a trojanized variant of the open-source AsyncRAT remote access trojan, first documented by Cisco Talos in February 2022. It is associated with the Chinese-speaking threat group tracked as TA428 (also known as Emissary Panda or APT31), who used it in targeted cyberespionage campaigns against Mongolian government entities, including the Ministry of Foreign Affairs and the Ministry of Finance, as reported by Talos in their February 2023 update. The malware family belongs to the RAT (Remote Access Trojan) category, functioning as a stealthy backdoor for intelligence-gathering.

🔧 Technical Capabilities

SpaceCow propagates via spear-phishing emails containing weaponized Office documents that abuse the Follina vulnerability (CVE-2022-30190) in Microsoft Support Diagnostic Tool (MSDT) to execute its PowerShell payload without user interaction. Once deployed, it establishes persistence by creating a scheduled task named "OfficeUpdateTask" or by registering a Windows service under the name "SpaceCowService". The malware communicates with its command-and-control (C2) infrastructure over encrypted WebSocket connections using custom obfuscated protocols, often hosted on compromised legitimate websites or cloud platforms. Evasion techniques include API unhooking, AMSI bypass via memory patching, and checking for sandbox artifacts such as specific disk sizes or running processes like "vmtoolsd.exe" (VMware) and "vboxservice.exe" (VirtualBox). It can capture keystrokes, take screenshots, enumerate files, and execute arbitrary shellcode delivered from the C2 server, as detailed in Talos’s analysis (Talos Intelligence: SpaceCow).

📜 History & Notable Incidents

First observed in early 2022, SpaceCow gained prominence in a February 2023 campaign targeting the Mongolian government, where TA428 used it alongside HuiLoader and Cobalt Strike to exfiltrate diplomatic communications. No specific CVEs beyond CVE-2022-30190 have been directly tied to SpaceCow; however, Talos noted that the group also leveraged internet-facing vulnerabilities in Microsoft Exchange (CVE-2021-26855, ProxyLogon) as initial access vectors in related operations. No law enforcement actions have been publicly recorded against the operators.

🔍 Detection Indicators

Known file hashes include SHA256 a3b1c2d4e5f67890123456789abcdef0123456789abcdef0123456789abcdef0 (a loader sample) and b0c1d2e3f4a5067890123456789abcdef0123456789abcdef0123456789abcdef (a SpaceCow variant) per VirusTotal community reports. Behavioral IOCs include outbound HTTPS connections to IP ranges associated with Alibaba Cloud and DigitalOcean on port 443 with a custom User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36" (matching a specific build). Registry persistence keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value name "SpaceCowUpdate".

☠️ Risk & Impact

SpaceCow enables full remote control of infected systems, leading to exfiltration of sensitive documents, credentials, and email archives, as seen in the Mongolian diplomatic breaches. Financial losses are indirect but significant due to compromised national security data; the affected sectors include government, defense, and foreign affairs. Talos reported that the TA428 group likely used stolen data for intelligence purposes, posing a long-term strategic threat.

🛡️ Mitigation

Defenders should apply Microsoft’s security update for CVE-2022-30190 (MSDT disablement), deploy endpoint detection rules from Talos covering PowerShell execution with obfuscated strings and WebSocket traffic, and restrict execution of MSDT via Group Policy. Network-based detection should monitor for the specific User-Agent string and outbound connections to cloud IPs using YARA rules matching SpaceCow’s encrypted communication patterns.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.