A custom 12 KB Windows backdoor was discovered on a single domain-joined Windows 7 SP1 workstation. The malware disguises itself as legitimate Realtek software and establishes persistence through a WMI event subscription that triggers at a specific time rather than during system startup. Its command-and-control domain is concealed through the number of trailing spaces in a fake `desktop.ini` file, while the malware communicates using ICMP and HTTP.
The backdoor collects a unique victim identifier based on system information and supports three commands: executing commands through `cmd.exe`, writing files to the system, and modifying its polling interval. It also uses techniques designed to evade basic file scanning, including disguising dropped executables and dynamically constructing command strings.[/subscribe_to_unlock_form]
A custom 12 KB Windows backdoor was discovered on a single domain-joined Windows 7 SP1 workstation. The malware disguises itself as legitimate Realtek software and establishes persistence through a WMI event subscription that triggers at a specific time rather than during system startup. Its command-and-control domain is concealed through the number of trailing spaces in a fake `desktop.ini` file, while the malware communicates using ICMP and HTTP.
The backdoor collects a unique victim identifier based on system information and supports three commands: executing commands through `cmd.exe`, writing files to the system, and modifying its polling interval. It also uses techniques designed to evade basic file scanning, including disguising dropped executables and dynamically constructing command strings.[emaillocker id="1283"]
The malware was observed on only one machine, with no evidence connecting it to a known threat actor or campaign. Its custom implementation, WMI persistence, concealed C2 configuration, and limited command set suggest it may have been selectively deployed rather than used in a widespread campaign.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.003 | Phishing | Spearphishing via Service |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Discovery | T1082 | System Information Discovery | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Discovery | E1082 | System Information Discovery |
| Execution | E1204 | User Execution |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
The following reports contain further technical details:
[/emaillocker]