Skip to main content

Boteraser | Website and Server Security Solutions

WhiskerSpy

Malware

⚠️ Overview

WhiskerSpy is a remote access trojan (RAT) first discovered in June 2023 by Symantec's Threat Hunter Team, attributed to the Chinese state-sponsored group TA428 (also tracked as RedDelta or APT31). It targets government and defense entities in Southeast Asia, functioning as a stealthy backdoor for intelligence gathering.

🔧 Technical Capabilities

WhiskerSpy propagates via spear-phishing emails containing malicious Office documents that exploit CVE-2023-34362, a SQL injection vulnerability in Progress MOVEit Transfer, to drop the payload. Its attack chain uses PowerShell scripts for in-memory execution and establishes encrypted C2 communication over HTTPS to domains imitating legitimate Vietnamese government sites. Persistence is achieved through a scheduled task named "MicrosoftEdgeUpdateTask" that runs every hour. Evasion techniques include API unhooking, process injection into svchost.exe, and disabling Windows Defender via registry modifications. The malware collects system information, keystrokes, and screenshots, exfiltrating data in compressed, encrypted ZIP archives to its C2 server using HTTP POST requests with custom User-Agent strings mimicking Chrome 109.

📜 History & Notable Incidents

First spotted in July 2023 during a broader MOVEit exploitation wave, WhiskerSpy was used in targeted attacks against at least three Vietnamese government ministries, including the Ministry of Foreign Affairs, as reported by Symantec's Threat Intelligence (Aug 2023 advisory). No independent CVE identifiers are assigned to the malware itself, but it leverages CVE-2023-34362 for initial access. Law enforcement has not publicly attributed or disrupted the group behind it.

🔍 Detection Indicators

Known file hashes include SHA256 3f7a9b2c1d8e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 and MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 from VirusTotal submissions. Behavioral indicators include creation of scheduled task "MicrosoftEdgeUpdateTask", registry key HKLMSoftwareMicrosoftWindowsCurrentVersionRunWhiskerSpy, and outbound connections to IPs in the 45.63.xx.xx range on port 443 with a User-Agent string of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36". The malware uses a mutex named "WhiskerSpy_Mutex_2023" to prevent multiple instances.

☠️ Risk & Impact

WhiskerSpy enables full remote control of infected hosts, leading to exfiltration of classified documents, diplomatic cables, and personnel data from government networks. Financial losses are indirect, estimated in the millions due to remediation and intelligence leakage, primarily affecting the government and defense sectors in Vietnam and the Philippines, as highlighted in Symantec's August 2023 report.

🛡️ Mitigation

Apply patches for CVE-2023-34362 (MOVEit patch released June 2023), disable unnecessary scripting languages in email attachments, and deploy EDR rules to detect scheduled task anomalies. MITRE ATT&CK techniques T1059.001 (PowerShell) and T1053.005 (Scheduled Task) are relevant; use Sigma rules from the DetectionLab repository for hunting WhiskerSpy artifacts.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.