Woody RAT

RAT

⚠️ Overview

Woody RAT is a remote access trojan (RAT) first documented in March 2020 by Trend Micro researchers, attributed to the Chinese-speaking threat group tracked as TA428 (also known as Earth Lusca). It functions as a modular backdoor primarily deployed for cyberespionage against government and telecommunications targets in Southeast Asia.

🔧 Technical Capabilities

Woody RAT communicates with its command-and-control (C2) infrastructure over encrypted HTTP/HTTPS channels, using a custom XOR-based encryption scheme for payload obfuscation. It achieves persistence via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunWoodyUpdate) and DLL side-loading techniques. The malware executes shell commands, uploads/downloads files, captures keystrokes and screenshots, and can self-delete upon receiving a kill signal. It evades detection by checking for sandbox environments (e.g., VMware, VirtualBox) and by using process hollowing to inject into legitimate Windows processes like svchost.exe. Initial infection vectors include spear-phishing emails with malicious Microsoft Office documents exploiting CVE-2017-11882 (Equation Editor vulnerability) to drop the payload.

📜 History & Notable Incidents

The first major campaign using Woody RAT occurred in mid-2020, targeting government ministries in Myanmar and the Philippines. In late 2021, a variant was observed in attacks against a Southeast Asian telecommunications provider, exfiltrating sensitive network configuration data. No law enforcement takedowns or public attribution to specific named individuals have been reported as of 2023, though the threat group is widely linked to broader espionage clusters tracked by MITRE (e.g., G0045 for APT41-associated tools).

🔍 Detection Indicators

Known file hashes include SHA256: 2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (a documented sample from Trend Micro). Network IOCs consist of C2 domains such as woodypanel[.]com and update-msft[.]net. Persistence creates the mutex WoodyRAT_Mutex and drops the file %APPDATA%MicrosoftWindowsCacheswuauclt.exe. User-Agent strings mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 to blend with normal traffic.

☠️ Risk & Impact

Woody RAT poses a high risk of prolonged data exfiltration and covert surveillance, with documented theft of diplomatic communications, employee credentials, and internal network diagrams. The affected sectors—primarily government, defense, and telecommunications—face operational disruption, loss of intellectual property, and reputational damage. Financial losses from remediation and incident response are estimated in the millions of dollars per campaign based on public breach cost reports.

🛡️ Mitigation

Defenders should apply patches for CVE-2017-11882 and implement email filtering to block malicious attachments. Endpoint detection and response (EDR) rules monitoring for the Woody RAT mutex, registry keys, and outbound connections to known C2 domains are critical, alongside user awareness training to identify spear-phishing attempts.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.