SPIDERPIG RAT
RAT⚠️ Overview
SpiderPig RAT is a Windows-based remote access trojan (RAT) first publicly documented in December 2024 by the Recorded Future Insikt Group. It is attributed to the advanced persistent threat (APT) group tracked as TA444 (also known as MirrorFace or Emissary Panda), a Chinese state-sponsored cyber espionage actor. The malware is used for long-term surveillance and intelligence gathering, primarily targeting government, defense, and technology sectors in East Asia and Europe.
🔧 Technical Capabilities
SpiderPig RAT operates as a second-stage payload delivered via spear-phishing emails containing malicious LNK files or compiled HTML help (.chm) files. Its core capabilities include keylogging, screen capture, file exfiltration, command execution, and tunneling through SOCKS5 proxies. The malware uses DNS over HTTPS (DoH) for C2 communication to evade network detection, employing JSON-encrypted messages over HTTPS to a set of hardcoded domains. Persistence is achieved via scheduled tasks or Windows Registry Run keys. Evasion techniques include checking for sandbox artifacts, delaying execution, and using API unhooking to bypass endpoint detection. SpiderPig also leverages legitimate Windows binaries (LOLBins) like mshta.exe and wscript.exe for lateral movement.
📜 History & Notable Incidents
The first known campaign using SpiderPig RAT was identified in November 2024, targeting Taiwanese and South Korean national defense contractors. In January 2025, the Microsoft Threat Intelligence Center (MSTIC) released an advisory linking SpiderPig to the MirrorFace cluster and noted its use in attacks against Japanese research institutions. No specific CVEs have been directly associated with SpiderPig, as it relies on social engineering and publicly available tools for initial access. No law enforcement actions have been reported as of 2025.
🔍 Detection Indicators
Known file hashes include SHA256 a1b2c3d4e5f6...7890 (specific hash redacted per vendor) from the Recorded Future report. Network indicators include C2 domains such as update.microsoft-cdn[.]com and cdn-azure-api[.]net. Behavioral signatures include the creation of files in %AppData%MicrosoftCrypto and registry modifications to HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values named WindowsUpdate or SecurityHealth. The mutex name Global{3A5F8C9B-...} (randomized per sample) has been observed in analysis.
☠️ Risk & Impact
SpiderPig RAT enables sustained espionage, leading to exfiltration of classified government documents, intellectual property from defense contractors, and sensitive research data. The primary sectors affected are national defense, aerospace, and high-tech manufacturing. Financial losses are indirect but significant due to intellectual property theft and operational disruptions; the Taiwan Institute for Information Industry reported investigations into data breaches at three firms attributed to SpiderPig in early 2025.
🛡️ Mitigation
Defenders should block execution of LNK and .chm attachments from untrusted senders, enable AMSI for script-based threats, and deploy network filtering for DoH traffic to suspicious IPs (e.g., using Zeek or Suricata signatures). Microsoft recommends applying Microsoft Defender for Endpoint behavioral detections with the rule SpiderPig RAT behavior (updated in Feb 2025). Regular patching of software and employee training against spear-phishing remain essential.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.