Asruex is a Windows malware family known since at least 2015 and associated with DarkHotel espionage activity. It is primarily documented as a backdoor, but some variants also function as a file infector. Reported capabilities include remote command-and-control communications, keystroke logging, password theft, data interception, and broader data theft from compromised hosts. In analyzed samples, Asruex also employed anti-debugging and anti-emulation checks and injected malicious code into legitimate Windows processes to support infection and backdoor operations.
Asruex has been observed delivered through trojanized software packages, including a compromised LAN driver installer distributed from a vendor support page, where execution with administrator privileges increased the impact of compromise. Variants have also spread through malicious shortcut files containing PowerShell-based download logic, removable drives, and network drives. File-infecting variants abused legacy vulnerabilities including CVE-2010-2883 in Adobe Reader/Acrobat and CVE-2012-0158 in Microsoft Word to execute in the background while displaying decoy document content to the victim. Those variants were capable of infecting PDF, Word, and executable files, allowing the malware to preserve normal-looking user experience while embedding malicious functionality.
Asruex is linked in public reporting to DarkHotel, a long-running espionage threat actor with a strong focus on targeted intrusions in Asia and on high-value government and enterprise victims. Some reporting has claimed DarkHotel used Asruex in operations involving isolated or air-gapped environments, but publicly available technical evidence for that specific use case has been assessed as insufficient in at least one major survey of air-gap malware. High-confidence reporting supports Asruex as a Windows backdoor with espionage-oriented collection features and, in some variants, document and executable infection capabilities that aid stealthy propagation and persistence in poorly patched environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Asruex ... can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 ... As mentioned earlier, it uses a specially crafted template to exploit the CVE-2012-0158 vulnerability to infect Word documents. The CVE-2012-0158 vulnerability allows possible attackers to execute an arbitrary code remotely through a Word document or web site. | Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883, which inject code in Word and PDF files respectively.
Asruex ... can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883, which inject code in Word and PDF files respectively... This behavior is due to a specially crafted template that takes advantage of the CVE-2010-2883 vulnerability while appending the host file. The vulnerability is found in the strcat function of Adobe’s CoolType.dll... it can cause a stack buffer overflow to execute its shellcode. | Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883, which inject code in Word and PDF files respectively.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
it has been reported that DarkHotel has used Asruex since 2015 to attack isolated networks; however, publicly available reports do not provide enough technical evidence demonstrating the presence of the minimal requirements needed to satisfy our working definition.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Asruex infects a system through a shortcut file that has a PowerShell download script
DarkHotel has repeatedly demonstrated its capabilities of developing exploits for 0day vulnerabilities in software such as Google Chrome, Mozilla Firefox, Internet Explorer, and Windows Kernel. The exploits are leveraged to deliver malware that can provide backdoor access and remote control over the target device.
The executable file also injects the DLL c982d2ab066c80f314af80dd5ba37ff9dd99288f ... into a legitimate Windows process memory.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware embedded in a compromised LAN driver that ran with administrator privileges, enabling keystroke logging, password theft, data interception, and communication with a command-and-control network.
A trojan detected within a downloadable Realtek LAN driver installer hosted on a legacy GEEKOM support page, creating a malware delivery route through a seemingly legitimate driver package.
A backdoor embedded in a Geekom LAN driver installer that would run with administrator privileges, steal data, intercept keystrokes, retrieve passwords, and connect to command-and-control servers for remote access.
Backdoor associated with DarkHotel; Tencent said attacks later incorporated the Asruex backdoor to attack isolated networks since 2015.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.