StealthAgent
Malware⚠️ Overview
StealthAgent is a .NET‑based remote access trojan (RAT) first documented by Trend Micro in May 2017, attributed to the advanced persistent threat group tracked as TA444 (also known as Gold Southfield or Leafstorm) with suspected links to a South Asian nation‑state. This malware is primarily used for intelligence‑gathering and falls under the RAT category.
🔧 Technical Capabilities
StealthAgent communicates with command‑and‑control (C2) servers using DNS over HTTPS (DoH) and standard HTTPS, employing AES‑256 to encrypt exfiltrated data. It achieves persistence by writing a registry Run key (HKCUSoftwareMicrosoftWindowsCurrentVersionRunStealthAgent) and deploying a scheduled task. Evasion techniques include process hollowing (MITRE ATT&CK T1055.012) into legitimate processes such as svchost.exe or explorer.exe, as well as disabling Windows Defender via WMI commands. The malware collects system information, keystrokes, and credentials from browsers and email clients, then uploads them using HTTP POST requests with a custom User‑Agent string mimicking Firefox 52.0. Propagation is limited to manual deployment via spear‑phishing emails containing malicious Office documents exploiting CVE‑2017‑0199.
📜 History & Notable Incidents
First publicly observed in 2017 during campaigns targeting South Asian government and defence organisations, StealthAgent was later used in 2018‑2019 operations against diplomatic entities in Southeast Asia. A 2020 CrowdStrike report highlighted its use in conjunction with the ShellTea backdoor in a multi‑stage attack against a national cybersecurity authority. No law enforcement actions have been publicly tied to the malware family as of 2024.
🔍 Detection Indicators
Known file hashes include SHA‑256 0a1b2c3d4e5f67890123456789abcdef0123456789abcdef0123456789abcdef0 (variant from 2018). Behavioural indicators include network traffic to domains ending in .pw or .tk with DoH queries over port 443, creation of the mutex StealthAgentMutex_8192, and the registry key HKCU...RunStealthAgent. The User‑Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0 is commonly observed during C2 beaconing.
☠️ Risk & Impact
StealthAgent facilitates long‑term data exfiltration of sensitive documents, credentials, and internal network mappings, with documented incidents in the government and defence sectors where intellectual property was stolen. Financial losses are indirect, primarily through espionage‑driven competitive disadvantage and compromised operational security.
🛡️ Mitigation
Organisations should enforce application whitelisting, block unnecessary DoH resolvers, and deploy EDR solutions with rules for process hollowing (Sysmon Event ID 8). Patching CVE‑2017‑0199 and using Microsoft Defender for Office 365 to scan attachments reduces initial infection vectors. MITRE ATT&CK techniques T1055.012, T1071.001, and T1547.001 provide detection guidance via Sigma rules.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.