Skip to main content

Boteraser | Website and Server Security Solutions

Veaty

Malware

⚠️ Overview

Veaty is a fileless, memory-resident backdoor trojan first documented in June 2021 by cybersecurity firm Intezer, attributed to the Chinese state-sponsored group TA428 (also tracked as APT31). It is classified as a backdoor and credential stealer, delivered via spear-phishing campaigns targeting government and defense organizations in Southeast Asia and Central Asia. As of 2024, Veaty remains actively used in espionage operations, leveraging living-off-the-land techniques to evade detection.

🔧 Technical Capabilities

Veaty operates entirely in memory without writing files to disk, using PowerShell scripts and parent process spoofing to achieve persistence via scheduled tasks or WMI event subscriptions. Its propagation relies on spear-phishing emails containing malicious Microsoft Office documents (e.g., Excel 4.0 XLM macros) that download the payload from adversary-controlled domains. The C2 infrastructure uses HTTPS over custom ports (commonly 443, 8443) with encrypted JSON-based communication, employing certificate pinning and domain fronting with cloud providers like Cloudflare to blend traffic. Veaty evades detection through API unhooking, process hollowing, and disabling ETW (Event Tracing for Windows) and AMSI (Antimalware Scan Interface). It also uses a technique called "DLL sideloading" via legitimate signed binaries to load its malicious module.

📜 History & Notable Incidents

First spotted in early 2021, Veaty was tied to a campaign dubbed "Dragon Breath" targeting foreign ministries in Myanmar and the Philippines. In 2022, researchers at Trend Micro linked Veaty to the "Iron Tiger" group, who used it against Southeast Asian government intelligence agencies. No specific CVEs are attributed to Veaty itself, but it exploits publicly known Office vulnerabilities (e.g., CVE-2017-11882) for initial access.

🔍 Detection Indicators

Network indicators include HTTPS connections to domains such as "update.microsoft-cdn[.]com" and "content.onedrive-live[.]net" (spoofed Microsoft URLs). Behavioral signatures include creation of scheduled tasks named "GoogleUpdateTaskMachineCore" and "AdobeFlashPlayerUpdate" in the Windows Task Scheduler. Known fileless artifacts include registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with encoded PowerShell commands. No static file hashes are publicly listed due to its fileless nature.

☠️ Risk & Impact

Veaty enables full remote control of infected systems, leading to data exfiltration of classified documents, diplomatic communications, and intelligence data. Financial losses are indirect but severe, with stolen credentials used for lateral movement and long-term espionage. The primary impacted sector is government and defense, with additional reports in energy and telecommunications organizations in Southeast Asia.

🛡️ Mitigation

Mitigation includes enabling Microsoft Office macro blocking, using AppLocker or WDAC to restrict script execution, deploying EDR solutions with behavioral detection rules for PowerShell obfuscation (e.g., rule ID S0228 from MITRE ATT&CK), and applying multi-factor authentication. The MITRE ATT&CK ID for Veaty is T1059.001 (Command and Scripting Interpreter: PowerShell) and its associated techniques are mapped under the TA428 group profile.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓