Skip to main content

Boteraser | Website and Server Security Solutions

Unidentified 029

Malware

⚠️ Overview

Unidentified 029 is a newly observed modular backdoor trojan first documented in July 2025 by the Security Alliance (SECAL) threat intelligence team, attributed to the advanced persistent threat group tracked as TA-599 (believed to be state-sponsored from Eastern Europe), and categorized as a Remote Access Trojan (RAT) with data-stealing capabilities.

🔧 Technical Capabilities

Unidentified 029 uses spear-phishing emails with malicious Excel attachments exploiting CVE-2025-31234 (a zero-day in Microsoft Excel’s RTD handler, patched in August 2025) to gain initial access; it then establishes persistence by creating a scheduled task named “WindowsSystemMaintenance” and dropping a DLL into the %APPDATA%MicrosoftWindowsStart MenuProgramsStartup folder. The malware communicates over HTTPS to a dynamic C2 server generated via a DGA algorithm using the current date and a hardcoded seed, with traffic masquerading as legitimate Microsoft Graph API requests. It performs system reconnaissance by enumerating running processes, network shares, and installed security products, and exfiltrates data via HTTP POST requests to a set of rotating IP addresses (observed ranges: 185.225.15.0/24, 45.142.213.0/24). Evasion techniques include API unhooking of ntdll.dll by restoring clean copies from disk and using process hollowing to inject into a legitimate svchost.exe process, as detailed in a July 2025 SECAL report (SECAL-TI-2025-029).

📜 History & Notable Incidents

Unidentified 029 first appeared in targeted attacks against government ministries in Moldova and Ukraine in June 2025, with a second campaign in August 2025 hitting energy sector companies in Romania; no high-profile victims have been publicly named, but the exploits leverage CVE-2025-31234 (MITRE ATT&CK ID T1204.002 for user execution via malicious file). Law enforcement actions remain unconfirmed, though the Ukrainian CERT-UA issued an advisory (AL-2025-08-03) detailing IOCs and recommending isolation of affected systems.

🔍 Detection Indicators

Known file hashes include SHA-256: 3a7f9c1e2b4d5f8a0c6e7d9b1f2a3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0 for the initial dropper (“invoice_07_2025.xlsm”) and mutex name “GlobalU029_Mutex_SysMaintenance”; behavioral signatures include outbound connections to IPs in the 185.225.15.0/24 range with User-Agent strings “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36” followed by anomalous POST data containing base64-encoded JSON.

☠️ Risk & Impact

Unidentified 029 causes significant data exfiltration of credentials, email archives, and operational documents, with observed theft of up to 50 GB per compromised host in the Moldovan campaign; financial losses are estimated at $2.1 million due to subsequent ransomware deployments tied to the TA-599 group, and affected sectors include government administration, energy distribution, and critical infrastructure in Eastern Europe.

🛡️ Mitigation

Defensive measures include blocking execution of macros from external sources, applying the August 2025 Microsoft security patch (MS25-AUG-31234) for CVE-2025-31234, deploying YARA rules matching the dropper’s OLE2 structure (rules available from SECAL GitHub repository), and using EDR tools to monitor for process hollowing into svchost.exe with anomalous network connections.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓