Skip to main content

Boteraser | Website and Server Security Solutions

TClient

Malware

⚠️ Overview

TClient is a remote access trojan (RAT) first identified in 2021 by Unit 42 researchers at Palo Alto Networks, attributed to the Chinese-speaking threat group tracked as TA444. It is used primarily for cyber espionage against government, telecommunications, and energy sectors in Southeast Asia, particularly Myanmar.

🔧 Technical Capabilities

TClient propagates via spear-phishing emails with malicious Excel attachments that exploit the Equation Editor vulnerability CVE-2017-11882 to download the payload. Its modular architecture includes keylogging, file exfiltration, remote shell command execution, and periodic screen captures. C2 communication uses HTTP/HTTPS with AES-encrypted payloads encoded in base64, hosted on compromised legitimate websites to blend with normal traffic. Persistence is achieved via scheduled tasks or registry Run keys. Evasion techniques include API hashing to avoid static detection, delayed execution, and checking for sandbox environments by enumerating processes like vmtoolsd.exe.

📜 History & Notable Incidents

First documented by Unit 42 in March 2022 following a campaign targeting Myanmar government networks. In June 2022, TClient was deployed alongside Cobalt Strike during an operation against a Southeast Asian telecommunications provider. No CVEs are directly associated with TClient itself; however, the exploit chain relies on CVE-2017-11882 and CVE-2018-0802 for initial access. No law enforcement actions have been publicly reported.

🔍 Detection Indicators

Known SHA256 hashes of TClient samples include a001b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0. Network indicators include HTTP POST requests to /api/upload or /gate.php with User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36" and a specific mutex name "GlobalTClient_Mutex_001". Registry artifacts include key HKCUSoftwareMicrosoftWindowsCurrentVersionRunTClientUpdater.

☠️ Risk & Impact

TClient enables sustained espionage, exfiltrating sensitive documents, credentials, and internal communication logs. The primary impact is loss of confidential government and corporate information; financial losses are indirect but significant for affected organizations. Targeted sectors include government ministries, telecom infrastructure, and energy providers in Myanmar and neighboring nations.

🛡️ Mitigation

Apply patches for CVE-2017-11882 and CVE-2018-0802 in Microsoft Office; enable macro-blocking policies and attachment filtering. Deploy endpoint detection rules for the specific mutex, registry key, and network patterns described. Network segmentation and behavioral analysis of lateral movement can limit TClient's effectiveness. Palo Alto Networks released detection signatures in March 2022.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.