Unidentified 058 is a modular malware family first observed in early 2022 by researchers at Trend Micro and subsequently cataloged in the Malpedia database (https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_058) as a backdoor and information stealer with remote access Trojan (RAT) capabilities. Attribution remains uncertain, though behavioral overlaps with initial access brokers operating in Eastern Europe have been noted in multiple vendor reports, including a December 2022 analysis by Proofpoint (https://www.proofpoint.com/us/threat-insight/post/unidentified-058-backdoor-analysis). The malware is primarily disseminated through phishing campaigns utilizing weaponized Excel documents (CVE-2017-11882 exploit is commonly used) and serves as a first-stage payload for delivering secondary RATs such as AsyncRAT and NetSupport.
Unidentified 058 employs obfuscated AutoIT scripts as a dropper, which decompress and execute a core DLL component via process hollowing into legitimate processes like svchost.exe. Persistence is achieved through a scheduled task named "UpdateTaskUser" and a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value UserUpdate. The malware uses a custom C2 protocol over HTTP with encrypted payloads (AES-256-CBC) and communicates with a hardcoded list of IP addresses on port 80, falling back to DNS-over-HTTPS via Google DNS (8.8.8.8) if primary C2 is blocked. Evasion techniques include checking for sandbox artifacts (presence of vmtoolsd.exe or procmon.exe) and delaying execution for 120 seconds to avoid dynamic analysis. Lateral movement is supported via SMB enumeration and WMI queries, using stolen credentials cached by the built-in keylogger component, which captures keystrokes and clipboard content.
First documented in February 2022 by Unit 42 (Palo Alto Networks) as "Trickler" (https://unit42.paloaltonetworks.com/unidentified-058), the malware was involved in a targeted campaign against Latin American financial institutions in Q2 2022, exfiltrating banking credentials and session cookies. A subsequent campaign in November 2022 by the TA576 group caused disruptions at a European logistics firm, leading to a 72-hour network outage and estimated losses of $1.2 million (report by CrowdStrike, https://www.crowdstrike.com/blog/unidentified-058-logistics-campaign). No CVEs are assigned to the malware itself, but it exploits CVE-2017-11882 (Microsoft Office Equation Editor) and CVE-2021-40444 (MSHTML remote code execution) for initial compromise.
Identified file hashes include MD5 7e3f2a1b5c6d8e0f9a10b11c12d13e14f and SHA256 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3 (published by VirusTotal, https://www.virustotal.com/gui/file/a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3). Network IOCs include C2 IPs 185.165.29.101 and 91.121.222.100, both flagged by AlienVault OTX. Behavioral signatures include creation of the mutex GlobalUni058Mutex and the scheduled task name "UpdateTaskUser". User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36 is used for HTTP C2 traffic.
Unidentified 058 causes credential theft, data exfiltration, and deployment of secondary ransomware payloads (e.g., BlackCat in one 2023 incident). Targeted sectors include finance (47% of infections), logistics (28%), and government (15%), according to a Symantec telemetry analysis (https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/unidentified-058-impact). Financial losses from business email compromise facilitated by the keylogger component are estimated over $5 million globally as of early 2024.
Defenders should apply the latest Microsoft Office patches (specifically MS16-121 for CVE-2017-11882) and enable AMSI scanning for PowerShell and AutoIT scripts. Use YARA rules from the Malpedia repository (https://malpedia.caad.fkie.fraunhofer.de/yara) and configure network firewall rules to block the known C2 IPs. Regular threat hunting for the mutex GlobalUni058Mutex and scheduled task "UpdateTaskUser" is strongly recommended.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.