Unidentified 061 is a malware family classification used by security vendors to denote a cluster of polymorphic trojan samples that could not be attributed to known threat actors. First observed in telemetry data from early 2020, it has no confirmed operator attribution and is primarily categorized as a downloader and backdoor, often delivering secondary payloads such as ransomware or information stealers. The designation appears in VirusTotal’s family tagging system and in some vendor detection names as a placeholder for unclassified malicious binaries.
Unidentified 061 employs obfuscation techniques including API hashing (using custom hash algorithms) and encrypted strings to evade static analysis. Persistence is achieved via scheduled tasks (MITRE ATT&CK T1053.005) and registry Run keys (T1547.001). Command and control (C2) communication uses HTTPS on port 443 with a non-standard User-Agent string mimicking legitimate browsers. The malware utilizes process hollowing (T1055.012) to inject its payload into legitimate processes such as svchost.exe. Evasion includes checking for virtual machine artifacts (e.g., presence of VMware tools) and disabling Windows Defender via registry modifications (T1562.001). Propagation appears limited to manual deployment; no self-replicating worm behavior has been documented in public reports.
The first known sample identified as Unidentified 061 was submitted to VirusTotal in March 2020 from a European financial institution. No major campaigns or high-profile victims have been publicly linked to this family, and no law enforcement actions or CVEs (Common Vulnerabilities and Exposures) have been specifically attributed to it. An academic paper from 2021 analyzing unclassified malware clusters references Unidentified 061 as a “low-prevalence” family with fewer than 500 samples globally.
Behavioral signatures include creation of a mutex named 061Mutex and writing a base64-encoded configuration file to %APPDATA%MicrosoftSettings.ini. Network indicators include periodic HTTPS beacons to IP ranges associated with bulletproof hosting providers (e.g., 45.xxx.xxx.xxx). Registry modifications commonly observed are HKCUSoftwareMicrosoftWindowsCurrentVersionRunSystemHelper pointing to a dropped executable. No publicly available file hashes are consistently associated due to polymorphic recompilation.
The primary risk of Unidentified 061 infection is the subsequent deployment of ransomware or credential-stealing malware, leading to data exfiltration and potential financial loss. Affected sectors are predominantly small-to-medium enterprises across healthcare, education, and finance, based on victim reports to national CERTs. The overall impact is considered moderate due to the malware’s low prevalence and lack of widespread campaign activity.
Defenders should enable real-time antivirus protection and deploy endpoint detection rules for the described mutex and registry indicators. Regular patching of Microsoft Office vulnerabilities (e.g., CVE-2017-11882) is critical as macro-based delivery is a suspected initial access vector. Network monitoring for anomalous HTTPS beaconing to known bulletproof hosting IPs can aid early detection.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.