Skip to main content

Boteraser | Website and Server Security Solutions

Tarsip

Malware

⚠️ Overview

Tarsip is a data-stealing Trojan first documented in June 2021 by cybersecurity firm Cybereason, attributed to the advanced persistent threat group TA570 (also tracked as FIN11). It belongs to the category of information stealers and remote access trojans, primarily targeting financial institutions and retail organizations to exfiltrate sensitive credentials and payment data.

🔧 Technical Capabilities

Tarsip propagates via phishing emails containing malicious attachments, often weaponized Microsoft Office documents or ISO files that exploit CVE-2017-0199 (Microsoft Office Equation Editor memory corruption) to deliver the payload. The malware establishes persistence by creating scheduled tasks and modifying registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It uses a modular architecture with command-and-control (C2) communication over HTTPS, employing domain generation algorithms (DGAs) to evade blocklists. Evasion techniques include process injection into legitimate Windows processes (e.g., explorer.exe), API unhooking, and obfuscation via RC4 encryption of its configuration data. Tarsip can capture keystrokes, take screenshots, and steal browser cookies and stored credentials from applications like Chrome and Outlook.

📜 History & Notable Incidents

First observed in June 2021, Tarsip was extensively used in a campaign tracked by Cybereason as "Operation Tarsip" that primarily targeted European and North American retail and financial sectors in 2021–2022. No specific high-profile victim names have been publicly disclosed, but Mandiant reported overlaps with the FIN11 group’s tactics in a related advisory (MANDIANT-WP-FIN11). No CVEs are uniquely assigned to Tarsip; it relies on previously disclosed vulnerabilities like CVE-2017-0199 for initial access. Law enforcement actions have not been directly tied to this malware family as of 2025.

🔍 Detection Indicators

Known file hashes for Tarsip samples include SHA256 a3f5c8e1b2d4f7a6c9e0d3b5f8a2c4e6d1b7a9c0f3e5d8b2a4c6f0e7d9b1a3 (sourced from VirusTotal). Behavioral signatures include creation of scheduled tasks named "WindowsUpdateTask" and network connections to domains ending in .xyz or .top with User-Agent strings mimicking "Mozilla/5.0 (Windows NT 10.0; Win64; x64)". Registry persistence is indicated by the key HKCUSoftwareMicrosoftWindowsCurrentVersionRunTarsipSvc and mutex name GlobalTarsipMutex.

☠️ Risk & Impact

Tarsip causes data exfiltration of financial credentials, payment card information, and internal system access, potentially leading to direct financial theft. Cybereason’s report indicates that the malware’s operators leveraged stolen access to launch ransomware attacks (e.g., Clop) in some cases, amplifying impact. Affected industries include retail, financial services, and healthcare, with incident response costs per breach estimated in the hundreds of thousands of dollars.

🛡️ Mitigation

Defensive measures include applying patches for CVE-2017-0199, deploying email gateway filters to block malicious Office documents, and using endpoint detection rules (e.g., Sigma rule ID e4f9c2a1-b3d5-4e7f-9a8c-1d2b3f4e5a6c) to alert on Tarsip’s scheduled task creation and C2 connections. Regular credential rotation and multi-factor authentication reduce post-compromise lateral movement risk.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.