Threat Advisory

Decoy Dog is based on Pupy, an open-source remote access trojan (RAT)

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

The researcher is discoverd the emergence and evolution of Decoy Dog, a sophisticated remote access trojan (RAT) based on the Pupy open-source RAT. The typical penetration testing tools, Decoy Dog showcases advanced features, including new commands, communication protocols, and upgraded Python 3.8 client, with significant modifications in core communication modules. The first sample of Decoy Dog was identified in September 2022, with subsequent samples appearing in 2023. Researchers found that encryption keys varied between servers, but samples communicating with com shared RSA and SSL keys. Notably, Decoy Dog introduced custom code allowing attackers to send and execute Java modules in a Java Virtual Machine (JVM) thread, a feature absent in standard Pupy versions.[/subscribe_to_unlock_form]

Summary:

The researcher is discoverd the emergence and evolution of Decoy Dog, a sophisticated remote access trojan (RAT) based on the Pupy open-source RAT. The typical penetration testing tools, Decoy Dog showcases advanced features, including new commands, communication protocols, and upgraded Python 3.8 client, with significant modifications in core communication modules. The first sample of Decoy Dog was identified in September 2022, with subsequent samples appearing in 2023. Researchers found that encryption keys varied between servers, but samples communicating with com shared RSA and SSL keys. Notably, Decoy Dog introduced custom code allowing attackers to send and execute Java modules in a Java Virtual Machine (JVM) thread, a feature absent in standard Pupy versions.[emaillocker id="1283"]

The Decoy Dog client underwent continuous development, with new functionalities and changes. Modules from the publicly available Pupy code were removed, and different samples exhibited diverse capabilities. The transition from Python 2.7 to Python 3.8 enhanced code quality and stability while ensuring Windows compatibility. A specific sample, uploaded in April 2023 but potentially dating back to mark the earliest public release, featuring added functionalities and support for Win32 targeting. the actors behind Decoy Dog demonstrated adaptability by porting exploit and communication modules to Windows, rewriting the picocmd client for DNS communications, and improving code stability. Later versions introduced an emergency module, utilizing Domain Generation Algorithms (DGA) to contact a third-party DNS server when communication with the C2 server faced prolonged disruption.

The highlights the inclusion of extensive persistence mechanisms in client version 3, suggesting intelligence operation characteristics. The most mature code, connecting to introduced two new commands, AlterDnsCncDomain and CompromisedNode, potentially indicating a shift in developers. Notably, the code departure from the rest and the use of version 4 suggests advanced development.

Threat Profile:

 

References:

Eventus Security Threat Research & Development Team

[/emaillocker]
crossmenu