EXECUTIVE SUMMARY
A newly discovered backdoor, identified as Backdoor.Msupedge, has been detected in an attack against a university in Taiwan. These backdoors employ a rare technique of communication with its command-and-control (C&C) server using DNS traffic. Although DNS tunneling is not entirely new, its application in this context is relatively uncommon, making this threat noteworthy.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A newly discovered backdoor, identified as Backdoor.Msupedge, has been detected in an attack against a university in Taiwan. These backdoors employ a rare technique of communication with its command-and-control (C&C) server using DNS traffic. Although DNS tunneling is not entirely new, its application in this context is relatively uncommon, making this threat noteworthy.[emaillocker id="1283"]
Backdoor.Msupedge is distributed as a dynamic link library (DLL) and is found in the following file paths: csidl_drive_fixed\xampp\wuplog.dll and csidl_system\wbem\wmiclnt.dll. The backdoor utilizes DNS tunneling, based on the publicly available dnscat2 tool, to facilitate communication with its C&C server. It processes commands received via DNS name resolution, with different behaviors determined by the third octet of the C&C server’s IP address. Commands include creating processes, downloading files, and managing temporary files. The initial intrusion is suspected to exploit CVE-2024-4577, a recently patched PHP vulnerability involving CGI argument injection. This flaw affects all versions of PHP on Windows systems and can lead to remote code execution if exploited.
The initial compromise appears to be linked to the exploitation of a recently patched PHP vulnerability CVE-2024-4577, a CGI argument injection flaw that affects all PHP versions on Windows. This vulnerability can lead to remote code execution if exploited. There has been recent activity from multiple threat actors scanning for systems vulnerable to this exploit. Currently, there is no clear attribution for the attack or understanding of the attackers' motives.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Discovery | T1083 | File and Directory Discovery |
| T1018 | Remote System Discovery | |
| Command and Control | T1132 | Data Encoding |
| T1071 | Application Layer Protocol | |
| T1105 | Ingress Tool Transfer | |
| Impact | T1565 | Data Manipulation |
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/hackers-use-php-exploit-to-backdoor-windows-systems-with-new-malware/