HomeSecuritySockDetour malware is used as a Windows backdoor

SockDetour malware is used as a Windows backdoor

The new custom SockDetour malware found on systems belonging to US defense contractors has been used as a backup backdoor to maintain access to compromised networks.

SockDetour

The malicious payload was discovered by security researchers at Unit 42, who believe that its operators kept the backdoor under the radar for a long time, as it has been in use by hackers since at least July 2019.

See also: Ransomware that hit Ukraine is being used as bait

SockDetour's stealthiness can be explained by the fact that it "runs fileless" on infected Windows servers by hijacking network connections, which makes it much more difficult to detect at the host and network level.

Connection hijacking is carried out using the legitimate Microsoft Detours library package.

In one of the attacks, the threat actors also used a very specific delivery server, a QNAP network-attached storage (NAS) device commonly used by small businesses that had been previously infected with the QLocker ransomware — they likely exploited the same security flaw (the CVE-2021-28799 remote code execution flaw) to gain access to the server.

Researchers first spotted the malware being deployed on the Windows server of at least one US defense contractor on July 27, 2021, which led to the discovery of three other defense organizations targeted by the same group with the same backdoor.

See also: CISA warns of exploited vulnerabilities in Zabbix servers

SockDetour malware is used as a Windows backdoor

How is it connected to China?

The SockDetour backdoor is used in attacks by a cluster of APT activities tracked by Unit 42 as TiltedTemple and has previously been linked to attacks exploiting various vulnerabilities in Zoho products, such as ManageEngine ADSelfService Plus (CVE-2021-40539) and ServiceDesk Plus271C (CVE-2021-40539).

Although the company did not attribute the SockDetour malware to a specific hacking group, Unit 42 researchers in November reported that the TiltedTemple campaign is the work of a Chinese-funded group tracked as APT27.

See also: Nvidia: Tool that overturns GPU restrictions was actually malware

The partial attribution is based on tactics and malicious tools that match APT27's past activity and similar targeting of the same range of industry sectors (e.g., defense, technology, energy, aerospace, government, and manufacturing) for cyber espionage.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS