CMSTAR is a Windows malware family used primarily as a custom downloader in cyber-espionage operations. It has been closely associated with the Lurid/Enfal ecosystem and has also been observed in campaigns that ultimately delivered additional payloads including BBSRAT as well as the backdoors PYLOT and BYEBY. Activity involving CMSTAR has targeted government entities, including campaigns against Mongolian and Belarusian government organizations, and has relied heavily on politically themed spearphishing lures.
CMSTAR has been delivered through weaponized Microsoft Office documents and archive-based lures. Document-based delivery has included exploitation of CVE-2012-0158 and CVE-2015-1641, as well as malicious macro-enabled Word documents. In some cases, archive attachments contained a disguised executable that launched CMSTAR through rundll32. Earlier reporting also linked CMSTAR delivery to malicious documents generated with the MNKit and Tran Duy Linh toolkits.
Functionally, CMSTAR acts as a downloader/loader that establishes execution on the victim host, resolves required APIs through a custom import reconstruction routine, decrypts embedded configuration data and strings, and contacts command-and-control infrastructure to retrieve or enable follow-on payloads. Its import resolution method is notable for enumerating export tables and matching API names through character-and-offset logic rather than relying on a normal import table. Observed variants have used obfuscation and encrypted configuration data, and have transmitted host profiling information to command-and-control servers over HTTP using simple encryption. Collected host data has included Windows version, CPU architecture, privilege level, and the presence of selected security software processes.
CMSTAR also supports persistence on Windows through autorun mechanisms and uses mutexes to prevent multiple concurrent instances. It has been observed enumerating running processes and hashing process names to identify security products without storing plaintext names. Reporting indicates this information is likely used to help operators assess or filter compromised systems. Multiple variants have been documented, including CMSTAR.A, CMSTAR.B, and CMSTAR.C, with differences in mutex usage and string-obfuscation routines.
Infrastructure and code relationships link CMSTAR to other Chinese nexus espionage tooling, especially Lurid/Enfal and Cmwhite, including overlapping command-and-control patterns and shared infrastructure characteristics. Campaign analysis has also highlighted code and tooling overlap with NetTraveler in some samples, supporting the assessment that CMSTAR has circulated within a broader ecosystem of espionage operators or shared malware suppliers rather than a single isolated intrusion set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Unit 42 is aware of threat actors using two toolkits - MNKit and the Tran Duy Linh toolkit - to produce malicious documents that exploit CVE-2012-0158 in order to implant Cmstar. | This specific downloader, Cmstar, is associated with the Lurid downloader also known as ‘Enfal’.
The newer documents containing exploits for both vulnerabilities appeared to use a publically available PoC authored by ‘HCL’, with little to no modifications made... All of the Microsoft Word documents leveraged in these attacks used the CVE-2012-0158 and CVE-2014-1761 exploits. | All of the weaponized documents except two executed the Cmstar loader or a lightly modified variant of Cmstar onto the victim host... Once Cmstar was loaded onto the victim hosts, it would attempt to retrieve a final payload... those that were available were variants of BBSRAT.
The RTF documents made use of CVE-2015-1641. This vulnerability, patched in 2015, allows attackers to execute malicious code when these specially crafted documents are opened within vulnerable instances of Microsoft Word. | Palo Alto Networks Unit 42 has identified a series of phishing emails containing updated versions of the previously discussed CMSTAR malware family targeting various government entities in the country of Belarus.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\xpsfiltsvcs: "rundll32.exe C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\xpsfiltsvcs.dll,XpsRegisterServer"
The Word documents, which we track as Werow, employ malicious macros for their delivery.
Unit 42 is aware of threat actors using two toolkits - MNKit and the Tran Duy Linh toolkit - to produce malicious documents that exploit CVE-2012-0158 in order to implant Cmstar.
The initial dropper embedded in the weaponized document files were obfuscated using a subtraction cipher previously used to obfuscate strings in the NetTraveler malware family.
...while displaying a decoy document or a legitimate appearing document that is generated and presented to the user to make it appear that the weaponized document that had been executed was indeed, legitimate.
For instance, the payload checks the EAT of "wininet.dll" using the comparisons mentioned above to find the address to the "DeleteUrlCacheEntryA" API function.
The SCR file mentioned previously drops a CMSTAR DLL and runs it via an external call to rundll32.exe.
Rather than including a list of strings of associated processes, Cmstar enumerates the running processes and subjects these process names to a hashing algorithm.
Each of the samples collected via WildFire and VirusTotal contained significant overlaps in tactics used, tools used, as well as infrastructure for command and control channels.
Cmstar also decrypts a 752-byte piece of shellcode that carries out communications with the C2 server, specifically by sending HTTP POST requests to the following URL
152 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced in historical threat intelligence through shared domain registration email infrastructure.
CMSTAR is the primary malware family used in the phishing campaign against Belarusian government targets. It is delivered via malicious Word documents with macros, RTF exploit documents using CVE-2015-1641, and a disguised SCR file. It downloads secondary payloads from remote servers, uses mutexes to ensure a single running instance, and serves as the delivery mechanism for additional backdoor payloads including PYLOT and BYEBY.
A downloader/loader used as the first-stage payload in most of the spear-phishing documents. It is dropped after exploitation of malicious Word documents, retrieves follow-on payloads such as BBSRAT, and shows code and obfuscation overlap with NetTraveler. The report describes it as closely related to Lurid/Enfal.
Custom downloader used in cyber espionage spear-phishing attacks. It is implanted via malicious documents exploiting CVE-2012-0158, manually builds its import address table, decrypts configuration and shellcode, establishes persistence via a Run registry key, gathers host information including AV process checks, and communicates with its C2 over HTTP POST.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.