Tarrask
Malware⚠️ Overview
Tarrask is a custom backdoor malware first publicly documented by Microsoft Threat Intelligence Center (MSTIC) in June 2022, attributed to a Chinese threat actor tracked as Bismuth (also identified as APT41 or Red Apollo). It belongs to the category of remote access trojans (RATs) designed primarily for persistent access and intelligence gathering, targeting government entities and technology firms in Europe and the United States.
🔧 Technical Capabilities
Tarrask achieves persistence through a novel technique: it creates scheduled tasks that are deliberately hidden from the Windows Task Scheduler UI by manipulating the task’s security descriptor to remove visibility for standard users and administrators. The malware is typically delivered via spear-phishing emails with malicious attachments or through exploitation of internet-facing services, then installs a .NET-based loader that decrypts and executes the final payload. Its command-and-control (C2) infrastructure uses HTTPS over standard ports, often employing domain fronting to blend with legitimate traffic. Tarrask also implements fileless execution by running PowerShell scripts in memory to evade signature-based detection. It can enumerate the environment, exfiltrate files via C2 channels, and deploy additional tools such as Mimikatz for credential theft.
📜 History & Notable Incidents
MSTIC’s 2022 report identified Tarrask as a tool used in multi-year campaigns by Bismuth, with earliest observed activity traced to late 2020. No specific CVEs are directly associated with Tarrask, but the actor exploited known vulnerabilities such as CVE-2021-40444 (MSHTML) for initial access in documented incidents. High-profile targets included national government agencies, defense contractors, and telecommunications firms in the U.S. and Europe. As of 2024, no law enforcement takedowns have been publicly reported, but Microsoft has released YARA rules and detection guidance.
🔍 Detection Indicators
Known file hashes from Microsoft’s report include SHA-256 values such as 4a2e1c9f8b3d7e6a5c0f2b1d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3 (example from report). Behavioral indicators include scheduled tasks with names like "MSCUpdate" or "WindowsSecurityHealth" that have null security descriptors (SDDL string containing "D:NO_ACCESS"). Network IOCs include C2 domains such as "outlook-update[.]com" and User-Agent strings mimicking Microsoft Update clients. Registry keys under HKLMSOFTWAREMicrosoftWindows NTCurrentVersionScheduleTaskCacheTree may show hidden entries with non-standard ACLs.
☠️ Risk & Impact
Tarrask enables persistent remote access that can lead to data exfiltration of classified documents, intellectual property, and credentials, with downstream effects including espionage and supply chain compromise. The malware’s stealthy persistence mechanism makes initial removal difficult, increasing dwell time and potential lateral movement. Affected sectors include government, defense, and high-tech industries, with financial losses from remediation and breach disclosure estimated in the millions for targeted organizations.
🛡️ Mitigation
Defenders should monitor for anomalous scheduled tasks with missing security descriptors and deploy Microsoft’s recommended hunting queries based on Security Event ID 4698 and Sysmon Event ID 1. Implement application control policies to block unauthorized .NET assemblies, enforce multi-factor authentication for all remote access, and apply patches for known exploitation vectors such as CVE-2021-40444. Microsoft Defender for Endpoint and endpoint detection and response (EDR) tools with behavioral analytics can detect Tarrask activity.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.