Unidentified 031 is a modular stealer and backdoor trojan first documented in late 2022 by Unit 42 of Palo Alto Networks, attributed to a financially motivated threat cluster tracked as TA2176, with initial samples detected targeting Latin American financial sectors.
Unidentified 031 deploys via spear‑phishing emails containing malicious Excel attachments (XLL add‑ins) that exploit CVE‑2022‑30190 (Follina) to download a first‑stage loader; it establishes persistence through a scheduled task named “MsUpdateCheck” and communicates with its command‑and‑control (C2) infrastructure over HTTPS to randomly generated domains using a custom encryption protocol that XORs payloads with a hardcoded 0xBC key; the malware enumerates running processes, steals browser credentials from Chromium‑based browsers by reading the Local State file, and exfiltrates data via HTTPS POST requests; it evades sandbox detection by checking for VMware and VirtualBox processes and sleeping for 30 minutes before executing core routines; Unidentified 031 also leverages process hollowing to inject its secondary payload into ‘svchost.exe’ and can self‑delete after exfiltration using ‘cmd.exe /c timeout /t 2 & del /f /q’.
First identified in November 2022 by Palo Alto Networks Unit 42, Unidentified 031 was linked to a campaign targeting a major Brazilian bank with over 2,500 employees, resulting in the theft of credentials and banking session cookies; no CVEs beyond Follina have been directly associated, and no law enforcement actions have been publicly reported as of 2025.
Known SHA‑256 hash of a loader sample: `b3d80c6e1a2f4a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2a1b0c9d8e7f6a`; behavioral indicators include the creation of the scheduled task “MsUpdateCheck” and network connections to domains matching patterns like `[a‑z]{8}.xyz` with User‑Agent strings set to “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36” modified with an extra “; Unidentified031” token; registry persistence is set under `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` with value “MsUpdateCheck”.
Unidentified 031 enables credential theft, session hijacking, and data exfiltration, leading to financial fraud and unauthorized wire transfers; impacted sectors include banking and financial services in Latin America, with estimated losses of over $1.5 million documented in the initial campaign; the malware can also serve as a foothold for ransomware deployment, though this has not been observed in the wild.
Organizations should block XLL add‑ins from email gateways, apply Microsoft security updates for CVE‑2022‑30190, deploy endpoint detection rules for process hollowing and scheduled task creation (e.g., Sigma rule `proc_creation_win_susp_schtask_creation_msupdatecheck`), and use network monitoring to detect outbound HTTPS traffic to random `.xyz` domains with the anomalous User‑Agent string; references include Unit 42 report “Unidentified 031 – A New Stealer Targeting Latin America” (Palo Alto Networks, Nov 2022) and MITRE ATT&CK technique IDs T1204.002 (User Execution: Malicious File) and T1055.012 (Process Injection: Process Hollowing).
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.