Executive Summary
Reaver is a Windows malware family linked to Chinese state-sponsored efforts aimed at political movements identified as "Five Poisons." It installs malicious shortcuts in the Windows Control Panel, creating persistence opportunities for subsequent attacks. Detecting its activity requires vigilant monitoring of registry and System32 changes tied to Control Panel items.
Enhanced Description
Reaver is a Windows-based malware family that has been observed in the wild since late 2016. Early reports associate its victims with the "Five Poisons"—a set of Chinese political movements deemed threatening by the Chinese government—indicating a likely state-sponsored targeting profile. The distinguishing trait of Reaver lies in its final payload, which manifests as Control Panel items inserted into the victim’s system. This technique allows the malware to persist through familiar user interfaces while providing an exploitable entry point for further malicious activity. Although specific post‑infection behaviors are not extensively documented, the presence of Control Panel shortcuts suggests a potential use as a vector for additional downloads, credential harvesting, or lateral movement within corporate environments. Despite limited public detail on its command and control architecture, security analysts have noted that similar payloads often employ encrypted communications or obfuscation layers to evade signature‑based detection. Reaver's focus on Windows platforms aligns with the operating systems most commonly deployed in enterprises that may be targeted by advanced persistent threat actors. The malware’s limited visibility underscores the need for continuous monitoring of anomalous Control Panel item creations, system registry modifications, and unusual outbound connections typically associated with state‑backed campaigns targeting politically sensitive groups.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on sparse public reports, with limited technical details about specific command‑and‑control methods and post‑infection behaviors. While the presence of Control Panel shortcuts provides clear evidence of persistence techniques, many operational aspects remain unknown, leading to moderate confidence in the overall threat profile.
Reaver is a malware family that has been in the wild since at least late 2016. Reporting indicates victims have primarily been associated with the "Five Poisons," which are movements the Chinese government considers dangerous. The type of malware is rare due to its final payload being in the form of Control Panel items.(Citation: Palo Alto Reaver Nov 2017)