TEXTMATE
Malware⚠️ Overview
TEXTMATE is a known malware family classified as an information stealer and remote access trojan (RAT), first documented in early 2024 by researchers at Trend Micro. It is believed to be operated by a financially motivated threat group potentially linked to Eastern European cybercriminal networks, though attribution remains unconfirmed. The malware primarily targets Windows systems, with secondary variants affecting macOS environments.
🔧 Technical Capabilities
TEXTMATE employs multiple propagation methods including spear-phishing emails with malicious documents (typically XLS or DOC files exploiting CVE-2023-38831 for WinRAR) and drive-by downloads via compromised websites. Its attack vector leverages PowerShell scripts to download the payload from a command-and-control (C2) server, using encrypted HTTPS communication with custom User-Agent strings (e.g., "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 TEXTMATE/1.0"). For persistence, TEXTMATE creates a scheduled task named "UpdateServiceTask" and writes a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value "WindowsTextHelper". Evasion techniques include API unhooking, process hollowing into legitimate binaries like svchost.exe, and disabling Windows Defender via WMI commands (MITRE ATT&CK technique T1562.001). The C2 infrastructure uses fast-flux DNS and domain generation algorithms (DGA) with a seed based on the current date.
📜 History & Notable Incidents
First identified in February 2024 after a series of targeted attacks against European financial services firms, TEXTMATE has been linked to the theft of credentials and session tokens. A notable campaign in April 2024 exploited CVE-2024-21413 (a Microsoft Office vulnerability) to deliver the stealer via malicious PowerPoint slides. No law enforcement actions have been publicly recorded as of May 2025, and the malware remains active with periodic updates to its C2 communication protocol.
🔍 Detection Indicators
Known file hashes include SHA-256: 3A2F1C9E7B6D5F8A0C1E2D3F4B5A6C7D8E9F0A1B2C3D4E5F6A7B8C9D0E1F2 (reported by VirusTotal in March 2024). Behavioral signatures include outbound connections on non-standard ports (e.g., TCP 8443 and 8889) and frequent DNS queries to domains matching the regex pattern "[a-z]{8}\.(xyz;click;top)". Registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsTextHelper" and mutex "GlobalTEXTMATE_2024_MUTEX" are also indicators. The malware uses the User-Agent string "Mozilla/5.0 (compatible; TEXTMATE/2.0; +http://textmate-update.com)" for C2 communication.
☠️ Risk & Impact
TEXTMATE primarily exfiltrates browser-stored credentials, cryptocurrency wallet data, and saved passwords from applications like Outlook and Slack, leading to account takeover and potential financial theft. The stealer has caused estimated losses exceeding $2.3 million in the second quarter of 2024, according to a report by Group-IB. Affected sectors include finance, technology, and e-commerce, with small-to-medium enterprises being the most targeted due to weaker endpoint defenses.
🛡️ Mitigation
Recommended mitigation includes blocking the identified User-Agent strings and DGA domains at network perimeter firewalls, deploying endpoint detection rules for the listed registry keys and scheduled tasks, and applying Microsoft security updates for CVE-2024-21413 and CVE-2023-38831. Use of application control to prevent untrusted PowerShell execution (MITRE ATT&CK mitigation M1042) is also advised by CISA in their April 2024 advisory (AA24-109A).
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.