CMSTAR

Aliases: meciv

First seen
2018-09-01 00:00:00
Malware type
trojan, rat
Family
Malware family
Profile updated
2026-07-07 13:03:31

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:us country_code:cn

Context

CMSTAR, also known as meciv, is a sophisticated Trojan and RAT used primarily for cyber-espionage. It often targets government and defense sectors in specific regions, leveraging advanced stealth capabilities.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Cmstar_Auto (yara-rule)

Reports & references

  • Palo Alto Unit 42 — Unit42 Threat Actors Target Government Belarus Using Cmstar Trojan (report)
  • researchcenter.paloaltonetworks.com — Digital Quartermaster Scenario Demonstrated In Attacks Against The Mongolian Government (report)
  • researchcenter.paloaltonetworks.com — Unit42 Threat Actors Target Government Belarus Using Cmstar Trojan (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cmstar (report)
  • twitter.com — 963829930776723461 (report)

External references