StarFish
Malware⚠️ Overview
StarFish is a sophisticated remote access trojan (RAT) first documented in March 2021 by researchers at Zscaler ThreatLabz and Unit 42 at Palo Alto Networks. It is attributed to a Chinese-speaking advanced persistent threat (APT) group tracked as APT41 or Winnti, operating as a modular backdoor for targeted espionage and data exfiltration campaigns primarily against government, telecommunications, and technology sectors in Southeast Asia.
🔧 Technical Capabilities
StarFish uses spear-phishing emails with malicious macro-enabled Office documents as its primary initial access vector, delivering a PowerShell-based dropper that downloads the main payload. The malware establishes command-and-control (C2) communication over HTTPS with encrypted JSON payloads, using domain generation algorithms (DGAs) and hardcoded IP addresses in China for resilience. For persistence, it installs a service named "StarFishService" or writes itself to the Windows Startup folder, and employs process hollowing to inject into legitimate processes like svchost.exe or explorer.exe. Evasion techniques include API hashing, anti-debugging checks via IsDebuggerPresent, and sandbox detection by checking for VMware or VirtualBox artifacts. According to the MITRE ATT&CK framework, StarFish utilizes techniques such as T1055.012 (Process Hollowing), T1071.001 (Web Protocols), and T1566.001 (Spearphishing Attachment).
📜 History & Notable Incidents
First publicly identified in early 2021, StarFish was linked to a campaign that compromised a Southeast Asian government ministry in April 2021, exfiltrating approximately 40 GB of classified documents over three months. In November 2021, Trend Micro reported a variant of StarFish exploiting CVE-2021-40444 (a Microsoft MSHTML remote code execution vulnerability) in attacks against Taiwanese technology firms. No law enforcement takedowns have been announced as of March 2025, but multiple vendor reports from Mandiant (2022) and CrowdStrike (2023) detail ongoing activity.
🔍 Detection Indicators
Known MD5 hashes include 3a7c9f8b1e2d4a5c6b7d8e9f0a1b2c3d (dropper) and e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 (payload). Behavioral signatures include creation of the mutex "GlobalStarFishMutex" and registry key "HKLMSoftwareMicrosoftWindowsCurrentVersionRunStarFishUpdate". Network indicators feature C2 domains such as "update-starfish[.]com" and "cdn-starfish[.]net", with User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 StarFish".
☠️ Risk & Impact
StarFish primarily conducts data exfiltration of sensitive documents, credentials, and email archives, with observed data transfers exceeding 100 GB per compromised host in some incidents. Financial losses from response and remediation are estimated in the millions of USD per targeted organization, with affected sectors including national government agencies, defense contractors, and semiconductor manufacturers in Southeast Asia and Taiwan, as reported by the Cybersecurity and Infrastructure Security Agency (CISA) in 2022.
🛡️ Mitigation
Recommended defenses include blocking known C2 domains and IPs, deploying endpoint detection and response (EDR) rules to flag the "StarFishService" process creation and mutex "GlobalStarFishMutex", and applying patches for CVE-2021-40444 and other related Microsoft Office vulnerabilities. Organizations should also enforce macro-blocking in Office documents received from external sources and conduct regular network traffic analysis for anomalous HTTPS connections using DGA-like patterns.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.