TClient is a remote access trojan (RAT) first identified in 2021 by Unit 42 researchers at Palo Alto Networks, attributed to the Chinese-speaking threat group tracked as TA444. It is used primarily for cyber espionage against government, telecommunications, and energy sectors in Southeast Asia, particularly Myanmar.
TClient propagates via spear-phishing emails with malicious Excel attachments that exploit the Equation Editor vulnerability CVE-2017-11882 to download the payload. Its modular architecture includes keylogging, file exfiltration, remote shell command execution, and periodic screen captures. C2 communication uses HTTP/HTTPS with AES-encrypted payloads encoded in base64, hosted on compromised legitimate websites to blend with normal traffic. Persistence is achieved via scheduled tasks or registry Run keys. Evasion techniques include API hashing to avoid static detection, delayed execution, and checking for sandbox environments by enumerating processes like vmtoolsd.exe.
First documented by Unit 42 in March 2022 following a campaign targeting Myanmar government networks. In June 2022, TClient was deployed alongside Cobalt Strike during an operation against a Southeast Asian telecommunications provider. No CVEs are directly associated with TClient itself; however, the exploit chain relies on CVE-2017-11882 and CVE-2018-0802 for initial access. No law enforcement actions have been publicly reported.
Known SHA256 hashes of TClient samples include a001b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0. Network indicators include HTTP POST requests to /api/upload or /gate.php with User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36" and a specific mutex name "GlobalTClient_Mutex_001". Registry artifacts include key HKCUSoftwareMicrosoftWindowsCurrentVersionRunTClientUpdater.
TClient enables sustained espionage, exfiltrating sensitive documents, credentials, and internal communication logs. The primary impact is loss of confidential government and corporate information; financial losses are indirect but significant for affected organizations. Targeted sectors include government ministries, telecom infrastructure, and energy providers in Myanmar and neighboring nations.
Apply patches for CVE-2017-11882 and CVE-2018-0802 in Microsoft Office; enable macro-blocking policies and attachment filtering. Deploy endpoint detection rules for the specific mutex, registry key, and network patterns described. Network segmentation and behavioral analysis of lateral movement can limit TClient's effectiveness. Palo Alto Networks released detection signatures in March 2022.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.