Skip to content
Malware family

Crimson

Crimson, also referred to as MSIL/Crimson, is a modular .NET remote access trojan (RAT) associated with Transparent Tribe.

Profile source: Mallory opens in a new tab

Crimson

Family profile

Crimson, also referred to as MSIL/Crimson, is a modular .NET remote access trojan (RAT) associated with Transparent Tribe. Reporting tied it to Operation Transparent Tribe, which targeted Indian diplomatic and military personnel through spearphishing emails, malicious websites, and weaponized documents exploiting CVE-2012-0158; one described infection chain used an exploit document to drop a downloader that retrieved the fuller-featured RAT from 213.136.87[.]122:10001. Transparent Tribe campaigns also used malicious VBA/VBS-based lures and drive-by pages to deliver Crimson alongside other tools.

Documented Crimson capabilities are consistent with espionage use. It can exfiltrate stolen information over its command-and-control channel using a custom TCP protocol; capture screenshots; capture webcam video; perform microphone/audio surveillance; identify the current user; identify the geographical location of the victim host; discover removable/pluggable drives; collect data from removable drives; steal credentials from web browsers; query installed anti-virus software; delete files from a compromised host; and use a Registry key to track installation duration and possibly versioning. Specifically, it checks HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\last_edate to determine how long it has been installed, and reporting also states it can set a Registry key for similar install-tracking/version purposes.

Additional reporting on MSIL/Crimson states it supports file theft, Outlook email theft, microphone recording, keylogging, browser credential theft, screenshots, webcam capture, and USB file collection. Observed infrastructure and indicators in the provided content include 213.136.87[.]122:10001, 193.37.152[.]28:9990, 5.189.145[.]248:10032, and lure- or delivery-related domains such as intribune.blogspot[.]com, avadhnama[.]com, cdrfox[.]xyz, afgcloud7[.]com, bbmsync2727[.]com, and attachment[.]biz subdomains.

Reported operators

Threat actors

1 named in public reporting
Transparent Tribe

After successful exploitation and decoding of the embedded payload, a family of malware we refer to as MSIL/Crimson will be executed on the victim’s machine. The first stage in infection is a downloader whose purpose is to download the more fully featured RAT component.

Exploited software

Vulnerabilities linked to Crimson

2 CVEs

MITRE ATT&CK

Crimson in ATT&CK

43 distinct techniques

Reporting

Research mentioning Crimson

Oct 31
Mitre Attack Website

System Location Discovery, Technique T1614 - Enterprise | MITRE ATT&CK®

Crimson can identify the geographical location of a victim host.

Oct 21
Mitre Attack Website

Updates - Updates - October 2021 | MITRE ATT&CK®

Software changes: ... Crimson

Mar 7
Mitre Attack Website

Command and Scripting Interpreter: Visual Basic, Sub-technique T1059.005 - Enterprise | MITRE ATT&CK®

Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host.

Mar 7
Mitre Attack Website

Audio Capture, Technique T1123 - Enterprise | MITRE ATT&CK®

Crimson can perform audio surveillance using microphones.

Mar 7
Mitre Attack Website

Query Registry, Technique T1012 - Enterprise | MITRE ATT&CK®

Crimson can check the Registry for the presence of HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\last_edate to determine how long it has been installed on a host.

Mar 7
Mitre Attack Website

Peripheral Device Discovery, Technique T1120 - Enterprise | MITRE ATT&CK®

Crimson has the ability to discover pluggable/removable drives to extract files from.

Mar 7
Mitre Attack Website

Software Discovery: Security Software Discovery, Sub-technique T1518.001 - Enterprise | MITRE ATT&CK®

Crimson contains a command to collect information about anti-virus software on the victim.

Mar 7
Mitre Attack Website

Query Registry, Technique T1012 - Enterprise | MITRE ATT&CK®

Crimson can check the Registry for the presence of HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\last_edate to determine how long it has been installed on a host.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.