Asruex is a Windows malware family associated with the DarkHotel espionage cluster and publicly linked to activity dating to at least 2015. It is primarily known as a backdoor that provides remote access to compromised systems and supports espionage-oriented collection, including password theft, keystroke interception, and broader data theft. In some observed intrusions, delivery through a trojanized driver installer allowed the malware to execute with administrative privileges, increasing its ability to persist and operate with elevated access.
Observed variants also extend beyond classic backdoor behavior and function as a file-infector targeting documents and executables. These variants have been documented infecting PDF and Microsoft Word files by exploiting legacy vulnerabilities including CVE-2010-2883 and CVE-2012-0158, while presenting the original host document to the victim to reduce suspicion. Asruex has also been observed infecting executable files so that the original program still runs, masking malicious execution. Supporting components perform anti-debugging and anti-emulation checks and inject malicious code into legitimate Windows processes, combining defense evasion with backdoor and infection functionality.
Propagation has been observed via shortcut-based execution chains using PowerShell, as well as through removable media and network drives. Public reporting has also tied Asruex to a supply-chain-style compromise in which a downloadable hardware driver package was trojanized, exposing users who manually installed the package. Asruex is therefore best characterized as a Windows backdoor with espionage capabilities that, in some variants, also incorporates file-infection and propagation features suited to stealthy persistence and spread in poorly patched or isolated environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Asruex ... can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 ... As mentioned earlier, it uses a specially crafted template to exploit the CVE-2012-0158 vulnerability to infect Word documents. The CVE-2012-0158 vulnerability allows possible attackers to execute an arbitrary code remotely through a Word document or web site. | Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883, which inject code in Word and PDF files respectively.
Asruex ... can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883, which inject code in Word and PDF files respectively... This behavior is due to a specially crafted template that takes advantage of the CVE-2010-2883 vulnerability while appending the host file. The vulnerability is found in the strcat function of Adobe’s CoolType.dll... it can cause a stack buffer overflow to execute its shellcode. | Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883, which inject code in Word and PDF files respectively.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
it has been reported that DarkHotel has used Asruex since 2015 to attack isolated networks; however, publicly available reports do not provide enough technical evidence demonstrating the presence of the minimal requirements needed to satisfy our working definition.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Asruex infects a system through a shortcut file that has a PowerShell download script
DarkHotel has repeatedly demonstrated its capabilities of developing exploits for 0day vulnerabilities in software such as Google Chrome, Mozilla Firefox, Internet Explorer, and Windows Kernel. The exploits are leveraged to deliver malware that can provide backdoor access and remote control over the target device.
The executable file also injects the DLL c982d2ab066c80f314af80dd5ba37ff9dd99288f ... into a legitimate Windows process memory.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor embedded in a Geekom LAN driver installer that would run with administrator privileges, steal data, intercept keystrokes, retrieve passwords, and connect to command-and-control servers for remote access.
Backdoor associated with DarkHotel; Tencent said attacks later incorporated the Asruex backdoor to attack isolated networks since 2015.
A malware family known for backdoor functionality that this report says also acts as a file/document infector. The variant infects systems via shortcut files containing PowerShell download scripts, spreads through removable and network drives, infects PDF, Word, and executable files, exploits old Adobe and Word vulnerabilities to execute in the background while showing the original host content, performs anti-debugging and anti-emulation checks, and injects a DLL into legitimate Windows processes to provide infection and backdoor capabilities.
Mentioned as a reported tool used against isolated networks, but excluded from the paper because available reporting did not provide enough technical evidence to meet the study's definition of air-gapped malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.