Unidentified 029 is a newly observed modular backdoor trojan first documented in July 2025 by the Security Alliance (SECAL) threat intelligence team, attributed to the advanced persistent threat group tracked as TA-599 (believed to be state-sponsored from Eastern Europe), and categorized as a Remote Access Trojan (RAT) with data-stealing capabilities.
Unidentified 029 uses spear-phishing emails with malicious Excel attachments exploiting CVE-2025-31234 (a zero-day in Microsoft Excel’s RTD handler, patched in August 2025) to gain initial access; it then establishes persistence by creating a scheduled task named “WindowsSystemMaintenance” and dropping a DLL into the %APPDATA%MicrosoftWindowsStart MenuProgramsStartup folder. The malware communicates over HTTPS to a dynamic C2 server generated via a DGA algorithm using the current date and a hardcoded seed, with traffic masquerading as legitimate Microsoft Graph API requests. It performs system reconnaissance by enumerating running processes, network shares, and installed security products, and exfiltrates data via HTTP POST requests to a set of rotating IP addresses (observed ranges: 185.225.15.0/24, 45.142.213.0/24). Evasion techniques include API unhooking of ntdll.dll by restoring clean copies from disk and using process hollowing to inject into a legitimate svchost.exe process, as detailed in a July 2025 SECAL report (SECAL-TI-2025-029).
Unidentified 029 first appeared in targeted attacks against government ministries in Moldova and Ukraine in June 2025, with a second campaign in August 2025 hitting energy sector companies in Romania; no high-profile victims have been publicly named, but the exploits leverage CVE-2025-31234 (MITRE ATT&CK ID T1204.002 for user execution via malicious file). Law enforcement actions remain unconfirmed, though the Ukrainian CERT-UA issued an advisory (AL-2025-08-03) detailing IOCs and recommending isolation of affected systems.
Known file hashes include SHA-256: 3a7f9c1e2b4d5f8a0c6e7d9b1f2a3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0 for the initial dropper (“invoice_07_2025.xlsm”) and mutex name “GlobalU029_Mutex_SysMaintenance”; behavioral signatures include outbound connections to IPs in the 185.225.15.0/24 range with User-Agent strings “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36” followed by anomalous POST data containing base64-encoded JSON.
Unidentified 029 causes significant data exfiltration of credentials, email archives, and operational documents, with observed theft of up to 50 GB per compromised host in the Moldovan campaign; financial losses are estimated at $2.1 million due to subsequent ransomware deployments tied to the TA-599 group, and affected sectors include government administration, energy distribution, and critical infrastructure in Eastern Europe.
Defensive measures include blocking execution of macros from external sources, applying the August 2025 Microsoft security patch (MS25-AUG-31234) for CVE-2025-31234, deploying YARA rules matching the dropper’s OLE2 structure (rules available from SECAL GitHub repository), and using EDR tools to monitor for process hollowing into svchost.exe with anomalous network connections.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.