Unidentified 073 (Charming Kitten)

Malware

⚠️ Overview

Unidentified 073 is a custom remote access trojan (RAT) attributed to the Iran-linked threat group Charming Kitten (also tracked as APT35, Phosphorus, TA453). First publicly documented in 2020 by ClearSky Cyber Security, this malware belongs to a toolkit used in targeted cyberespionage campaigns against academics, journalists, and human rights activists, primarily in the Middle East and the United States. Unidentified 073 is distinct from other Charming Kitten tools by its heavy reliance on legitimate cloud services for command-and-control (C2), a technique that helps it evade traditional network detection.

🔧 Technical Capabilities

Unidentified 073 propagates via spear-phishing emails using social engineering lures, often impersonating academic conferences or news organizations. Attachment payloads are usually malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) to drop the RAT payload. Once executed, the trojan establishes persistence by creating a scheduled task named "AdobeUpdateTask" and modifies the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun. C2 communication is layered: initial beaconing uses HTTP GET requests to legitimate services like Dropbox or Google Drive, then the malware retrieves a second-stage encrypted payload hosted on Telegram channel posts (as observed by Proofpoint in 2021). Evasion techniques include API hashing to avoid import address table hooks, encrypted strings using XOR with a hardcoded key (0xAB), and a check for sandbox environment artifacts such as the presence of WMI debugging tools. Data exfiltration is performed via HTTPS POST requests mimicking normal web traffic, often to attacker-controlled email accounts or cloud storage APIs.

📜 History & Notable Incidents

Unidentified 073 first appeared in February 2020 in a campaign targeting Iranian diaspora journalists, according to a report by Citizen Lab (March 2020). In November 2021, researchers at Mandiant linked the same malware to a wave of attacks against U.S. think tanks and former intelligence officials, using decoy invitations to a fictitious "Iranian Resistance Summit." No law enforcement actions have been publicly attributed to dismantling the operation, though U.S. Treasury sanctions were imposed on affiliated individuals in 2022. The malware does not exploit CVEs beyond CVE-2017-11882 for initial delivery, but its C2 infrastructure regularly rotates domains hosted on Iranian ASes.

🔍 Detection Indicators

File hashes recorded by VirusTotal (SHA256: e30a2b8c9d1e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9) are associated with a 2020 sample. Behavioral signatures include outbound HTTPS connections to api.telegram.org or drive.google.com with unusual User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/88.0 containing injected HTTP headers for authentication tokens. Registry persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value name "AdobeUpdate" points to %APPDATA%adobeupdate.exe. Mutex names include GlobalAdobeSecurityCheck.

☠️ Risk & Impact

Unidentified 073 poses a high risk for targeted individuals, enabling full remote access for credential theft, document exfiltration, and keystroke logging. Affected sectors are primarily academia, media, and human rights organizations — victims have reported loss of confidential research and personal email accounts. No widespread financial losses have been recorded, but the espionage impact undermines national security and freedom of expression, as noted in a 2022 Human Rights Watch report.

🛡️ Mitigation

Defenders should block execution of Office documents with macros from external senders, implement network monitoring for anomalous connections to cloud APIs (e.g., Telegram bot endpoints), and deploy YARA rules matching the XOR-encrypted strings and API hashing patterns documented by Mandiant (M-Trends 2022). Application whitelisting and enabling Attack Surface Reduction rules in Microsoft Defender can also prevent persistence via scheduled tasks.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.