Cotx RAT is a Windows remote-access trojan used by the China-linked TA428 threat group in Operation LagTime IT, a cyber-espionage campaign targeting government agencies in East Asia since at least 2019. It was delivered through spear-phishing lures containing Royal Road-generated RTF documents exploiting Microsoft Equation Editor vulnerability CVE-2018-0798. The malware executes through DLL side-loading of a malicious library by a legitimate signed executable. Cotx RAT stores encrypted configuration data, uses AES-192 and Base64 encoding, and communicates using proxy-aware TLS traffic. It collects host identifiers and network-system details, and supports file operations, screenshot capture, process and installed-software enumeration, shell access, configuration updates, and self-removal. TA428 also used Poison Ivy and credential-theft and network-reconnaissance tooling alongside Cotx RAT during post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
攻撃者はEternal Blueを悪用して同一ネットワーク上のいくつかのホストに移動することに成功すると、そのうちの1つのホスト上で興味深いマルウェアを動かし始めました。
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Operation LagTime IT ... Using Royal Road RTF Weaponizer, Poison Ivy and Cotx RAT. ... Cotx RAT - The original RAT used by TA428.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
We observed the following commands: 5 - Open command shell 6 - Open command shell as logged in user 7 - Send command to command shell
Spear phishing emails included malicious .doc attachments that were actually RTF files saved with .doc file extensions.
The initial beacon contains “|”-delimited system information... Computer name... Username... Windows version... Architecture... Local IP addresses... First adapter's MAC address
We observed the following commands: 2 - Get directory info or drive info
After that, it communicates with the C&C server just like the first Poison Ivy.
The command and control structure of Cotx RAT is proxy aware. It utilizes wolfSSL for TLS encrypted communication.
The command and control structure of Cotx RAT is proxy aware... Proxy IP and port discovered by searching the IPv4 TCP connection table for established connections with remote ports using common proxy ports (3128, 8080, 808, 1080) Or via WINHTTP_OPTION_PROXY.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TA428が使う他のRATとして比較目的でのみ言及。
A remote access trojan used by TA428 in targeted attacks.
攻撃者がコンピュータの制御を得るために使用したRAT。
Custom remote access trojan written in C++ and delivered via malicious RTF/Equation Editor exploitation. It is side-loaded through RasTls.dll, stores encrypted configuration in a .cotx PE section and the registry, communicates over TLS via proxy-aware C2, and supports commands including shell access, file operations, screenshots, process control, configuration updates, and self-removal.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.