Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware CARROTBAT

CARROTBAT

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

CARROTBAT is a Windows dropper that delivers the SYSCON RAT via custom installers, using shared infrastructure with KONNI. It gains persistence through registry keys and communicates over HTTPS to exfiltrate data and receive commands. Continuous vigilance against its download vectors and command servers remains critical for affected organizations.

Enhanced Description

CARROTBAT is a sophisticated, Windows‑based dropper that has been observed in the wild since at least 2017.^1 The tool’s primary function is to deliver a secondary payload—most notably the SYSCON backdoor—which establishes persistence and facilitates remote command and control operations. CARROTBAT leverages custom installers and stealthy download mechanisms, allowing attackers to sidestep antivirus detection by employing obfuscated binaries and encrypted network traffic. Operational analyses reveal that CARROTBAT shares infrastructure with the well‑known KONNI ransomware group, suggesting a common threat actor or shared supply chain for command‑and‑control servers. The dropper typically initiates through malicious attachments or drive‑by downloads, gains foothold via user execution of the installer, and then writes its payload to privileged system directories before adding self‑executing entries in the Windows registry (e.g., HKLM\Software\Microsoft\Windows\CurrentVersion\Run). Once deployed, SYSCON opens a persistent channel back to the attacker’s command server using HTTP/S, enabling data exfiltration, lateral movement, and credential theft. The long deployment window indicates an ongoing threat actor campaign that regularly updates both infrastructure and payload variants. Despite limited public attribution, security researchers have documented several distinct CARROTBAT infections across multiple industries, underscoring the need for continuous monitoring of known domain patterns and file signatures associated with this family.

Key Capabilities

  • Custom Windows installer (dropper) that bypasses AV detection
  • Deploys SYSCON RAT as secondary payload
  • Implements persistence via Run Key entries in HKLM/WIN10 registry
  • Downloads additional binaries over HTTPS with encrypted traffic
  • Exfiltrates data and receives commands through secure sockets
  • Shares command‑and‑control infrastructure with KONNI group

ATT&CK Techniques

T1059
T1071.001
T1071.003
T1105
T1204
T1060

Recommended Actions

  • Block outbound connections to known CARROTBAT/CN servers and associated IP ranges

Suggested Tags

malware
dropper
Windows
RAT
SYSCON
KONNI
command-and-control
persistent
downloader

Confidence Assessment

The confidence in the core capabilities—dropper function, deployment of SYSCON, and persistence tactics—is moderate due to corroborated evidence from Unit 42 reports. However, specific technical details such as exact encryption methods, complete command set, and full threat actor attribution remain uncertain, creating gaps that warrant further investigation.

Description

CARROTBAT is a customized dropper that has been in use since at least 2017. CARROTBAT has been used to install SYSCON and has infrastructure overlap with KONNI.(Citation: Unit 42 CARROTBAT November 2018)(Citation: Unit 42 CARROTBAT January 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.