CMSTAR
Aliases: meciv
- First seen
- 2018-09-01 00:00:00
- Malware type
- trojan, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 13:03:31
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:us country_code:cn
Context
CMSTAR, also known as meciv, is a sophisticated Trojan and RAT used primarily for cyber-espionage. It often targets government and defense sectors in specific regions, leveraging advanced stealth capabilities.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Cmstar_Auto (yara-rule)
Reports & references
- Palo Alto Unit 42 — Unit42 Threat Actors Target Government Belarus Using Cmstar Trojan (report)
- researchcenter.paloaltonetworks.com — Digital Quartermaster Scenario Demonstrated In Attacks Against The Mongolian Government (report)
- researchcenter.paloaltonetworks.com — Unit42 Threat Actors Target Government Belarus Using Cmstar Trojan (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Cmstar (report)
- twitter.com — 963829930776723461 (report)