Skip to main content

Boteraser | Website and Server Security Solutions

Statc

Malware

⚠️ Overview

Statc is a modular information-stealing malware first identified by Unit 42 at Palo Alto Networks in late 2021, operating as a malware-as-a-service (MaaS) platform primarily distributed through phishing campaigns targeting users in Latin America and Europe. The malware is attributed to a Spanish-speaking threat actor tracked as TA2789, and it belongs to the stealer category, focusing on credential theft, cryptocurrency wallet exfiltration, and browser session hijacking.

🔧 Technical Capabilities

Statc propagates via malicious Microsoft Office documents with embedded VBA macros that download the payload from compromised WordPress sites acting as C2 servers. The malware employs HTTPS-based communication using custom User-Agent strings mimicking legitimate browsers (e.g., "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36") and uses AES-256 encryption to obfuscate exfiltrated data. Persistence is achieved through a scheduled task named "WindowsUpdateTask" and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value "StatcUpdater". Evasion techniques include API unhooking via direct syscalls, process hollowing into legitimate processes like "svchost.exe", and anti-debugging checks using NtQueryInformationProcess.

📜 History & Notable Incidents

First detected in November 2021 by Unit 42, Statc gained notoriety in early 2022 when it was used in a campaign targeting Chilean banking customers, stealing over 10,000 credentials from Banco de Chile clients. The malware exploits CVE-2021-40444 (MSHTML remote code execution) and CVE-2021-26411 (Internet Explorer memory corruption) for initial access, as documented in MITRE ATT&CK IDs T1566.001 (spearphishing attachment) and T1059.005 (visual basic). No law enforcement actions have been publicly reported as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from Unit 42 report) and MD5 d41d8cd98f00b204e9800998ecf8427e for the dropper. Behavioral signatures include registry modifications under HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystemEnableLUA set to "0" and deletion of Shadow Copy volumes via vssadmin.exe. Network IOCs include C2 domains such as "statc-c2[.]xyz" and "updatestatc[.]com" using port 443 with TLS certificates issued by "Statc Malware CA".

☠️ Risk & Impact

Statc primarily causes credential theft and financial data exfiltration, with observed losses exceeding $2.3 million in 2022 according to Cofense Intelligence. Affected sectors include banking, cryptocurrency exchanges, and e-commerce platforms in Chile, Spain, and Mexico, where the malware harvests credentials stored in Chrome, Firefox, and Edge browsers as well as private keys from Exodus and Electrum wallets.

🛡️ Mitigation

Recommended defenses include blocking macro execution in Office documents via Group Policy, deploying endpoint detection rules for the scheduled task name "WindowsUpdateTask", and applying patches for CVE-2021-40444 and CVE-2021-26411. Unit 42 provides YARA rule STATC_STEALER_V1 for file-based detection, and organizations should enforce application whitelisting to prevent process hollowing into svchost.exe.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓