Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a campaign targeting Cambodian users documented in 2017, KHRAT operators used a project-themed Word document to persuade recipients to enable macros, then abused built-in Windows utilities to schedule execution and retrieve or run additional code. Palo Alto Networks Unit 42 also documented lookalike domains and compromised Cambodian government servers in the delivery infrastructure. The contemporaneous reporting associated KHRAT with China-linked group DragonOK; that is a reported association, not independently established attribution.

How the campaign targeted Cambodian users

On June 21, 2017, a malicious Word file was uploaded to Palo Alto Networks’ WildFire service. Its filename was “Mission Announcement Letter for MIWRMP phase 3 implementation support mission, June 26-30, 2017(update).doc.” It invoked the Mekong Integrated Water Resources Management Project, a World Bank-funded initiative concerning water and fisheries management in northeastern Cambodia. The project-specific administrative framing was intended to make the document relevant to its recipients.

The document asked recipients to enable macros. If they did, its Document_Open VBA macro ran. This made the recipient’s interaction with the warning a key execution trigger: the lure was not simply an attachment, but an attempt to get the user to authorize embedded code.

Which Windows tools were abused

Unit 42 described several built-in Windows components used by the analyzed sample. These are observed techniques in that sample, not instructions for reproducing them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Stage Component or technique Reported role
Scheduled execution schtasks.exe The macro created a scheduled task to support continued execution.
Retrieving additional content rundll32.exe with JavaScript-related parameters and mshtml.dll The sample used this combination to invoke code that retrieved further content.
Remote script handling regsvr32.exe Unit 42 reported its use with a remote script component to download and execute script content.

These are legitimate Windows utilities, but their presence alone does not prove an infection. The concern is their context—for example, unexpected Office activity followed by unusual task creation or use of these tools to access remote content. Unit 42 characterized the use of multiple built-in applications as a way to remain inconspicuous, and as a change from earlier KHRAT variants.

How the infrastructure disguised the activity

One documented hostname was update.upload-dropbox[.]com, which imitated a familiar file-sharing brand in its name. The word “Dropbox” in a hostname did not make the connection legitimate. Unit 42 also reported actor-registered domains resembling travel services and infrastructure that included compromised Cambodian government servers.

In a related chain described in the report, a small executable was disguised with a .jpg extension and hosted on compromised Cambodian government servers. The analyzed sample launched regsvr32.exe, which retrieved a script-like file named logo.ico. That script enumerated running processes through Windows Management Instrumentation and sent the list to a PHP endpoint. When researchers checked, the server did not respond to the POST; the operator’s intended next step was therefore not established. Unit 42 also said the exact contents and purpose of two referenced .ico files were unavailable to researchers.

The hostnames and server details are historical indicators from the 2017 report, not current blocklist guidance. A familiar brand embedded in a domain should be checked by validating the full hostname and destination independently.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What KHRAT could do after delivery

Unit 42 described KHRAT as a remote-access Trojan with keylogging, screenshot capture, and remote-shell capabilities. It said the malware registered victims using the infected machine’s username, system language, and local IP address. These capabilities describe what the malware could do; they do not establish that every capability was used against every target in this campaign.

What the 2017 activity figures do—and do not—show

Unit 42 observed just over 50 KHRAT network sessions across Palo Alto Networks sensors since the beginning of 2017, with a small uptick shortly before its August 31 report. That is a view of sessions seen by those sensors, not a count of unique infected machines, victims, or worldwide prevalence.

The report also gave broader telemetry figures for the behaviors used in the campaign: more than 3,000 malicious sessions per day on average exhibiting scheduled-task behavior, and about one malicious session per day on average for the rundll32/JavaScript behavior discussed. These figures were not KHRAT-only rates and should not be treated as measures of this campaign’s scale.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Practical defensive takeaways

  • Treat unexpected Office files and requests to enable macros cautiously, especially when they invoke a current project, meeting, or administrative process.
  • Investigate unexpected scheduled-task creation and unusual use of rundll32.exe or regsvr32.exe, particularly when related to Office activity or remote content.
  • Validate the complete hostname and destination rather than trusting a recognizable brand name embedded in a domain.

These are defensive implications of the reported chain, not a guarantee that any single control would have prevented the activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources and historical scope

Palo Alto Networks Unit 42 published its technical analysis, “Updated KHRAT Malware Used in Cambodia Attacks,” on August 31, 2017: Unit 42 report. SecurityWeek summarized the findings on September 1, 2017, and described KHRAT as associated with the China-linked DragonOK group: SecurityWeek coverage. These sources document activity observed in 2017; they do not establish that KHRAT or this campaign remains active today.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.