Veaty is a fileless, memory-resident backdoor trojan first documented in June 2021 by cybersecurity firm Intezer, attributed to the Chinese state-sponsored group TA428 (also tracked as APT31). It is classified as a backdoor and credential stealer, delivered via spear-phishing campaigns targeting government and defense organizations in Southeast Asia and Central Asia. As of 2024, Veaty remains actively used in espionage operations, leveraging living-off-the-land techniques to evade detection.
Veaty operates entirely in memory without writing files to disk, using PowerShell scripts and parent process spoofing to achieve persistence via scheduled tasks or WMI event subscriptions. Its propagation relies on spear-phishing emails containing malicious Microsoft Office documents (e.g., Excel 4.0 XLM macros) that download the payload from adversary-controlled domains. The C2 infrastructure uses HTTPS over custom ports (commonly 443, 8443) with encrypted JSON-based communication, employing certificate pinning and domain fronting with cloud providers like Cloudflare to blend traffic. Veaty evades detection through API unhooking, process hollowing, and disabling ETW (Event Tracing for Windows) and AMSI (Antimalware Scan Interface). It also uses a technique called "DLL sideloading" via legitimate signed binaries to load its malicious module.
First spotted in early 2021, Veaty was tied to a campaign dubbed "Dragon Breath" targeting foreign ministries in Myanmar and the Philippines. In 2022, researchers at Trend Micro linked Veaty to the "Iron Tiger" group, who used it against Southeast Asian government intelligence agencies. No specific CVEs are attributed to Veaty itself, but it exploits publicly known Office vulnerabilities (e.g., CVE-2017-11882) for initial access.
Network indicators include HTTPS connections to domains such as "update.microsoft-cdn[.]com" and "content.onedrive-live[.]net" (spoofed Microsoft URLs). Behavioral signatures include creation of scheduled tasks named "GoogleUpdateTaskMachineCore" and "AdobeFlashPlayerUpdate" in the Windows Task Scheduler. Known fileless artifacts include registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with encoded PowerShell commands. No static file hashes are publicly listed due to its fileless nature.
Veaty enables full remote control of infected systems, leading to data exfiltration of classified documents, diplomatic communications, and intelligence data. Financial losses are indirect but severe, with stolen credentials used for lateral movement and long-term espionage. The primary impacted sector is government and defense, with additional reports in energy and telecommunications organizations in Southeast Asia.
Mitigation includes enabling Microsoft Office macro blocking, using AppLocker or WDAC to restrict script execution, deploying EDR solutions with behavioral detection rules for PowerShell obfuscation (e.g., rule ID S0228 from MITRE ATT&CK), and applying multi-factor authentication. The MITRE ATT&CK ID for Veaty is T1059.001 (Command and Scripting Interpreter: PowerShell) and its associated techniques are mapped under the TA428 group profile.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.