Summary:
Exfiltrator-22, often known as EX-22, is a new post-exploitation framework that aims to quietly deliver ransomware into enterprise networks. With such a vast range of capabilities, anyone who buys the tool will find post-exploitation to be a piece of cake. The malware creators are based in North, East, or Southeast Asia and are probably no longer associated with the LockBit ransomware business.[/subscribe_to_unlock_form]
Summary:
Exfiltrator-22, often known as EX-22, is a new post-exploitation framework that aims to quietly deliver ransomware into enterprise networks. With such a vast range of capabilities, anyone who buys the tool will find post-exploitation to be a piece of cake. The malware creators are based in North, East, or Southeast Asia and are probably no longer associated with the LockBit ransomware business.[emaillocker id="1283"]
The malware targets x64-architecture-based devices. The buyers of EX-22 tool would be given a login panel to access the Ex22 server, which is hosted on a secured VPS (Virtual Private Server). Threat actors can use this panel to remotely manage the malware they have installed on affected machines. Reverse shell was elevated so that Exfiltrator-22 may open a network connection from an infected device to a remote server. Exfiltrator-22 can download and upload files once it has taken over a device. It can also trace every entrance log, encrypt the files, and demands ransom. It can collect screenshots and create a live connection to victim's machine. It has the capacity to gain more system privileges and extract sensitive data. The panel also enables threat actors to automate processes like rolling out new malware versions, changing the infection's setup, or developing new campaigns.
With constant upgrades and support, EX-22 becomes a go-to solution for any threat actors seeking to acquire tools for the post exploitation phase but do not want to go with the usual tools due to high detection rates. EX-22 is marketed as completely undetectable.
Threat Profile:
| Tactic | Technique Id | Technique |
| Execution | T1129 | Shared Modules |
| Persistence | T1547 | Boot or Logon AutoStart Execution |
| Privilege Escalation | T1055 | Process Injection |
| T1134 | Access Token Manipulation | |
| Defense Evasion | T1497 | Virtualization/Sandbox Evasion |
| T1027 | Obfuscated Files or Information | |
| T1112 | Modify Registry | |
| T1134 | Access Token Manipulation | |
| T1564 | Hide Artifacts | |
| T1620 | Reflective Code Loading | |
| Credential Access | T1056 | Input Capture |
| Discovery | T1082 | System Information Discovery |
| T1010 | Application Window Discovery | |
| T1057 | Process Discovery | |
| T1083 | File and Directory Discovery | |
| Collection | T1113 | Screen Capture |
| Impact | T1486 | Data Encrypted for Impact |
References:
The following reports contain further technical details:
https://thehackernews.com/2023/02/new-ex-22-tool-empowers-hackers-with.html
[/emaillocker]