Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Reaver

Reaver

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

Reaver is a Windows malware family linked to Chinese state-sponsored efforts aimed at political movements identified as "Five Poisons." It installs malicious shortcuts in the Windows Control Panel, creating persistence opportunities for subsequent attacks. Detecting its activity requires vigilant monitoring of registry and System32 changes tied to Control Panel items.

Enhanced Description

Reaver is a Windows-based malware family that has been observed in the wild since late 2016. Early reports associate its victims with the "Five Poisons"—a set of Chinese political movements deemed threatening by the Chinese government—indicating a likely state-sponsored targeting profile. The distinguishing trait of Reaver lies in its final payload, which manifests as Control Panel items inserted into the victim’s system. This technique allows the malware to persist through familiar user interfaces while providing an exploitable entry point for further malicious activity. Although specific post‑infection behaviors are not extensively documented, the presence of Control Panel shortcuts suggests a potential use as a vector for additional downloads, credential harvesting, or lateral movement within corporate environments. Despite limited public detail on its command and control architecture, security analysts have noted that similar payloads often employ encrypted communications or obfuscation layers to evade signature‑based detection. Reaver's focus on Windows platforms aligns with the operating systems most commonly deployed in enterprises that may be targeted by advanced persistent threat actors. The malware’s limited visibility underscores the need for continuous monitoring of anomalous Control Panel item creations, system registry modifications, and unusual outbound connections typically associated with state‑backed campaigns targeting politically sensitive groups.

Key Capabilities

  • Creates persistent entries via Control Panel shortcuts
  • Potentially uses obfuscated or encrypted C2 communication
  • Targets Windows systems associated with political movements
  • May download additional payloads after initial installation

ATT&CK Techniques

T1060 (Registry Run Keys / Startup Folder)
T1059 (Command and Scripting Interpreter)
T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder)

Recommended Actions

  • Implement granular file integrity monitoring to detect new Control Panel items and registry keys
  • Configure endpoint detection solutions to alert on unauthorized shortcut creation in control panel locations
  • Deploy network segmentation to limit lateral movement from infected hosts
  • Enable logging of outbound connections for forensic correlation
  • Maintain up‑to‑date antivirus signatures focused on known Reaver variants

Suggested Tags

Chinese state-sponsored malware
Five Poisons targeting
Windows Control Panel Trojan
Malware family

Confidence Assessment

The analysis is based on sparse public reports, with limited technical details about specific command‑and‑control methods and post‑infection behaviors. While the presence of Control Panel shortcuts provides clear evidence of persistence techniques, many operational aspects remain unknown, leading to moderate confidence in the overall threat profile.

Description

Reaver is a malware family that has been in the wild since at least late 2016. Reporting indicates victims have primarily been associated with the "Five Poisons," which are movements the Chinese government considers dangerous. The type of malware is rare due to its final payload being in the form of Control Panel items.(Citation: Palo Alto Reaver Nov 2017)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.