Telemiris is a remote access trojan (RAT) first documented by Fortinet's FortiGuard Labs in March 2021, attributed to a Spanish-speaking threat actor tracked as APT-C-36 (also known as Blind Eagle). The malware is primarily used for espionage and data theft targeting government entities and financial institutions in Colombia and Latin America.
Telemiris spreads via spearphishing emails containing malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) to execute shellcode. The RAT establishes persistence through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Its command-and-control (C2) infrastructure uses HTTP POST requests with encrypted payloads, often employing dynamic DNS domains to evade blocklists. Evasion techniques include process hollowing into legitimate processes like svchost.exe, API unhooking, and checking for sandbox environments by verifying mouse movement and system uptime. The malware can capture keystrokes, take screenshots, exfiltrate files, and execute arbitrary commands retrieved from the C2 server.
First observed in early 2021, Telemiris campaigns escalated in 2022 targeting the Colombian National Police and several energy-sector organizations. In March 2023, a variant was linked to the theft of sensitive data from Ecuador's Ministry of Economy and Finance. No specific CVEs beyond CVE-2017-11882 have been publicly documented for Telemiris itself; no law enforcement actions have been reported.
Known SHA-256 hashes include a3f5b8c1d2e4f6a7b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 (from Fortinet's analysis). Behavioral indicators include outbound HTTP POST requests to domains using patterns like telemiris[.]com or random subdomains on free Dynamic DNS providers (e.g., no-ip.org). Registry artifacts include the mutex GlobalTelemiris_Mutex and the registry key HKLMSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate pointing to a dropped binary named wuauclt.exe.
Telemiris enables complete remote control of infected systems, leading to credential theft, exfiltration of classified documents, and lateral movement within victim networks. The primary impact is on government and financial sectors in Colombia and Ecuador, with incidents resulting in operational disruption and loss of sensitive data. Financial losses are estimated in the tens of millions due to remediation costs and stolen intellectual property.
Organizations should block macro execution in Office documents from untrusted sources, apply patch MS17-014 for CVE-2017-11882, and deploy endpoint detection and response (EDR) solutions with behavioral rules for process injection and outbound encrypted traffic to dynamic DNS domains. Network-level blocking of known malicious domains and sandbox analysis of email attachments are recommended as per Fortinet's March 2021 report.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.