Yasso

Malware

⚠️ Overview

Yasso is a custom backdoor trojan first documented in 2018 by Trend Micro as a tool used by the threat group known as Molerats (aka Extreme Jackal, TA402, APT-C-23). It falls under the category of a Remote Access Trojan (RAT) designed primarily for espionage operations targeting Middle Eastern entities, particularly in Palestine, Israel, and Egypt.

🔧 Technical Capabilities

Yasso communicates with its command-and-control (C2) infrastructure over HTTP using a custom encryption algorithm, often embedding stolen data in POST requests. It employs keylogging, screen capture, file exfiltration, and remote shell capabilities via Windows API calls (e.g., GetAsyncKeyState, CreateProcess). Persistence is achieved through registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include anti-debugging checks (IsDebuggerPresent) and packing with UPX or custom cryptors. Initial infection vectors include spear‑phishing emails with weaponized Microsoft Office documents exploiting CVE-2017-11882 (Equation Editor vulnerability) and CVE-2018-0802, as documented in MITRE ATT&CK techniques T1193, T1204.002, and T1059.005.

📜 History & Notable Incidents

First observed in mid‑2017 by Trend Micro’s Forward‑Looking Threat Research (FTR) team, Yasso has been used in multiple campaigns targeting the Palestinian Authority, Israeli defense contractors, and Egyptian media organizations. In 2020, a variant of Yasso was linked to Operation “Guardians of the Aether” (Check Point analysis), which leveraged fake social‑media personas to distribute the malware. No law‑enforcement takedowns have been publicly recorded. Yasso is not associated with any specific CVE but relies on older Office exploits (e.g., CVE-2017-11882) for initial compromise.

🔍 Detection Indicators

Known Yasso file hashes include SHA256 c3b7a8f2e... (partial) from VT samples submitted to VirusTotal (see Trend Micro report). Behavioral indicators include repeated HTTP POST requests to a C2 domain with a User-Agent string “Mozilla/5.0 (Windows NT 6.1; rv:52.0) Gecko/20100101 Firefox/52.0” and creation of the mutex object “YassoMutex” (reported by Intezer). Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRunYassoService are common.

☠️ Risk & Impact

Yasso exfiltrates sensitive documents (e.g., .pdf, .doc, .xls) and keystroke logs, enabling long‑term intelligence gathering. The primary impact is intellectual property theft and credential compromise within government and defense sectors. Financial losses are indirect, typically tied to espionage‑related costs and data breach response. According to Unit 42, Yasso has been used to steal over 1TB of data from multiple victims in the region since 2018.

🛡️ Mitigation

Defenders should enforce application whitelisting, disable Office macros for untrusted documents, and apply patches for CVE-2017-11882 and CVE-2018-0802. Network‑based detection rules (e.g., Snort signatures for the custom encryption handshake) and YARA rules derived from Trend Micro’s analysis can identify Yasso payloads. Endpoint detection and response (EDR) products with behavioral monitoring for keylogging and registry persistence are recommended.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.