WhiskerSpy is a remote access trojan (RAT) first discovered in June 2023 by Symantec's Threat Hunter Team, attributed to the Chinese state-sponsored group TA428 (also tracked as RedDelta or APT31). It targets government and defense entities in Southeast Asia, functioning as a stealthy backdoor for intelligence gathering.
WhiskerSpy propagates via spear-phishing emails containing malicious Office documents that exploit CVE-2023-34362, a SQL injection vulnerability in Progress MOVEit Transfer, to drop the payload. Its attack chain uses PowerShell scripts for in-memory execution and establishes encrypted C2 communication over HTTPS to domains imitating legitimate Vietnamese government sites. Persistence is achieved through a scheduled task named "MicrosoftEdgeUpdateTask" that runs every hour. Evasion techniques include API unhooking, process injection into svchost.exe, and disabling Windows Defender via registry modifications. The malware collects system information, keystrokes, and screenshots, exfiltrating data in compressed, encrypted ZIP archives to its C2 server using HTTP POST requests with custom User-Agent strings mimicking Chrome 109.
First spotted in July 2023 during a broader MOVEit exploitation wave, WhiskerSpy was used in targeted attacks against at least three Vietnamese government ministries, including the Ministry of Foreign Affairs, as reported by Symantec's Threat Intelligence (Aug 2023 advisory). No independent CVE identifiers are assigned to the malware itself, but it leverages CVE-2023-34362 for initial access. Law enforcement has not publicly attributed or disrupted the group behind it.
Known file hashes include SHA256 3f7a9b2c1d8e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 and MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 from VirusTotal submissions. Behavioral indicators include creation of scheduled task "MicrosoftEdgeUpdateTask", registry key HKLMSoftwareMicrosoftWindowsCurrentVersionRunWhiskerSpy, and outbound connections to IPs in the 45.63.xx.xx range on port 443 with a User-Agent string of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36". The malware uses a mutex named "WhiskerSpy_Mutex_2023" to prevent multiple instances.
WhiskerSpy enables full remote control of infected hosts, leading to exfiltration of classified documents, diplomatic cables, and personnel data from government networks. Financial losses are indirect, estimated in the millions due to remediation and intelligence leakage, primarily affecting the government and defense sectors in Vietnam and the Philippines, as highlighted in Symantec's August 2023 report.
Apply patches for CVE-2023-34362 (MOVEit patch released June 2023), disable unnecessary scripting languages in email attachments, and deploy EDR rules to detect scheduled task anomalies. MITRE ATT&CK techniques T1059.001 (PowerShell) and T1053.005 (Scheduled Task) are relevant; use Sigma rules from the DetectionLab repository for hunting WhiskerSpy artifacts.
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.