HomeSecurityNew Windows backdoor based on PowerShell detected

New PowerShell-based Windows backdoor discovered

Researchers have shared new details about a PowerShell-based backdoor used by the Project Raven hacking group. They have found that the malware shares strong similarities with the Win32/StealthFalcon backdoor created by the Stealth Falcon hacking group.

New PowerShell-based Windows backdoor discovered
What are the new findings?

According to ESET 's latest findings , the malware appears to be the work of a state-sponsored government espionage group called Project Raven

Both Win32/StealthFalcon and the anonymous PowerShell-based backdoor share the same C2 server. Furthermore, significant similarities were found in the code, although they are written in different languages.

"Both use identifiers with a hardcoded key (most likely campaign ID/target ID). In both cases, all network from the compromised host are appended with these identifiers and encrypted with RC4 using a hardcoded key," researchers added.

The Stealth Falcon hacking group has been active since 2012 and mostly targets residents of the United Arab Emirates.

PowerShell

About Win32/StealthFalcon

Win32/StealthFaclon, which appears to have been created in 2015, can allow attackers to remotely control the compromised computer. The malware has targeted users in the UAE, Saudi Arabia, Thailand, and the Netherlands.

During its communication with the C2 server, the malware uses the Windows Background Intelligent Transfer Service (BITS) to transfer large amounts of data.

BITS includes commendable features that make it popular over traditional communication via API.

backdoor

"BITS is designed to transfer large amounts of data without consuming large amounts of network bandwidth, which it achieves by sending the data at a rate that does not interfere with the needs of other applications. It is commonly used by updaters, messengers , and other applications designed to run in the background."

What are the possibilities?

Win32/StealthFalcon, if executed on a system, is capable of being scheduled as a task that runs on every user login. In addition, it can exfiltrate data, use other malicious tools, and update its configuration.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS