Threat Advisory

Custom Windows Backdoor Disguises Itself as Realtek Software

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A custom 12 KB Windows backdoor was discovered on a single domain-joined Windows 7 SP1 workstation. The malware disguises itself as legitimate Realtek software and establishes persistence through a WMI event subscription that triggers at a specific time rather than during system startup. Its command-and-control domain is concealed through the number of trailing spaces in a fake `desktop.ini` file, while the malware communicates using ICMP and HTTP.

The backdoor collects a unique victim identifier based on system information and supports three commands: executing commands through `cmd.exe`, writing files to the system, and modifying its polling interval. It also uses techniques designed to evade basic file scanning, including disguising dropped executables and dynamically constructing command strings.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A custom 12 KB Windows backdoor was discovered on a single domain-joined Windows 7 SP1 workstation. The malware disguises itself as legitimate Realtek software and establishes persistence through a WMI event subscription that triggers at a specific time rather than during system startup. Its command-and-control domain is concealed through the number of trailing spaces in a fake `desktop.ini` file, while the malware communicates using ICMP and HTTP.

The backdoor collects a unique victim identifier based on system information and supports three commands: executing commands through `cmd.exe`, writing files to the system, and modifying its polling interval. It also uses techniques designed to evade basic file scanning, including disguising dropped executables and dynamically constructing command strings.[emaillocker id="1283"]

The malware was observed on only one machine, with no evidence connecting it to a known threat actor or campaign. Its custom implementation, WMI persistence, concealed C2 configuration, and limited command set suggest it may have been selectively deployed rather than used in a widespread campaign.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.003 Phishing Spearphishing via Service
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Discovery T1082 System Information Discovery -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Persistence F0012 Registry Run Keys / Startup Folder
Discovery E1082 System Information Discovery
Execution E1204 User Execution
Anti-Static Analysis B0032 Executable Code Obfuscation
Anti-Static Analysis E1027 Obfuscated Files or Information

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu