HomeSecurityScript to remove the DoublePulsar backdoor

Script to remove the DoublePulsar backdoor

The security company Countercept offers the ability to remotely uninstall the DoublePulsar backdoor from any Windows system, with the help of a python-based script it created for this purpose.

DoublePulsar

The software is open source and available for free through the popular code hosting and sharing platform Github: https://github.com/countercept/doublepulsar-detection-script

For those who don't know, DoublePulsar is one of multiple hacking tools leaked online a few days ago by the infamous hacking group Shadow Brokers. These tools are allegedly in the NSA's arsenal and can be used to compromise any Windows system.

According to recent research, tens of thousands of infected computers have been identified so far, with the number constantly increasing. The main exploit used to compromise systems is Eternalblue, which installs the DoublePulsar backdoor on infected systems. DoublePulsar exploits a vulnerability in the Windows SMB protocol, allowing remote access to any computer and the interception of information.

Countercept's script promises to detect and remove the backdoor in question. As the company explains, "The SMB version [of the script] supports remote uninstallation of the backdoor, aided by the analysis of the opcode mechanism via reverse engineering by @zerosum0x0.".

“Removing the backdoor from an infected system is as easy as rebooting the system, although this will not prevent a re-infection. Installing the corresponding patch provided by Microsoft will fix the vulnerability, effectively protecting you from DoublePulsar.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS