ESET researchers, while analyzing a cyberattack against targets in the Middle East, have identified a technically interesting downloader. The malware uses several odd techniques, one of which stands out: the registration of a new local system port monitor named “Default Print Monitor.”.
Because of this technique, ESET researchers named the downloader DePriMon, and, given its complexity and modular architecture, they consider it to be a malware framework.
According to ESET telemetry, the DePriMon malware has been active since at least March 2017. It was detected on a private company based in Central Europe and on dozens of computers in the Middle East. In some cases, DePriMon was detected together with the ColoredLambert malware, used by the Lamberts (also known as Longhorn) cyberespionage group and linked to the Vault 7 leak.
ESET researchers believe that DePriMon is a highly advanced downloader, and that its creators have put significant effort into structuring its architecture and synthesizing its important functions. Therefore, it is worth paying attention to other elements beyond the limited geographical distribution of its targets and its possible association with a known cyberespionage group.
DePriMon installs itself into memory and executes directly from there as a DLL file using the DLL loading technique. It is never stored on disk. It has a surprisingly extensive configuration file with interesting elements, its encryption is properly implemented, and it effectively protects communication with its C&C. As a result, DePriMon is a powerful, flexible, and resilient tool, designed to receive and execute a payload, and then collect some basic information about the system and its users.
To help users stay safe from this threat, ESET researchers have thoroughly analyzed this newly discovered malware, focusing on its installation technique, which has been classified in the MITRE ATT&CK as “Port Monitors”, in the “Persistence” and “Privilege Escalation” tactic categories.
As no actual case of this technique has been recorded in the MITRE ATT&CK database, ESET researchers believe that DePriMon is the first example of the “Port Monitors” technique to be publicly described.
More details can be found in the article "Registers as a Default Print Monitor, but is a malicious downloader. Meet DePriMon" on WeLiveSecurity.
