HomeinetResearchers warn about MystRodX Backdoor

Researchers warn about MystRodX Backdoor

Cybersecurity researchers have uncovered the new, silent MystRodX backdoor, which has a variety of features to capture sensitive data from compromised systems.

See also: UK: Drops order for backdoor in Apple iCloud

MystRodX Backdoor

“MystRodX is a typical backdoor implemented in C++, supporting functions such as file management, port forwarding, reverse shell, and socket management,” QiAnXin XLab said in a report published last week. “Compared to typical backdoors, MystRodX stands out in terms of its silent operation and flexibility.”

The MystRodX backdoor, also known as ChronosRAT, was first documented by Palo Alto Networks Unit 42 last month in connection with a threat activity cluster called CL-STA-0969, which shows overlap with a Chinese cyberespionage group called Liminal Panda.

The malware's silent operation comes from using various layers of encryption to hide its source code and payloads, while its flexibility allows for the dynamic activation of different features based on a configuration, such as selecting TCP or HTTP for network communication or selecting plain text or AES encryption for securing network traffic.

The MystRodX backdoor also supports what is called a wake-up function, allowing it to act as a passive backdoor that can be activated upon receiving specially crafted DNS or ICMP packets from incoming traffic. There is evidence to suggest that the malware may have been around since at least January 2024, based on an activation timestamp set in the configuration.

“When the magic value is verified, MystRodX establishes communication with the C2 [command-and-control] using the specified protocol and awaits further commands,” the XLab researchers said. “Unlike known silent backdoors like SYNful Knock, which manipulate TCP header fields to hide commands, MystRodX uses a simpler but effective approach: it hides the activation instructions directly in the payload of ICMP packets or within DNS queries.”

See also: Hackers target Russian companies with the EAGLET backdoor

Researchers warn about MystRodX Backdoor
MystRodX Backdoor

The malware is delivered via a dropper that uses a series of checks related to debugging and virtual machines to determine whether the current process is localized or running in a virtualized environment. Once the validation step is complete, the next-stage payload is decrypted. It contains three components:

1. daytime, a launcher responsible for starting chargen
2. chargen, the backdoor component of MystRodX

The MystRodX backdoor, once executed, continuously monitors the daytime process and if it is not found to be running, it starts it immediately. Its configuration, which is encrypted using the AES algorithm, contains information regarding the C2 server, the backdoor type, and the primary and backup C2 ports.

“When the Backdoor Type is set to 1, the MystRodX Backdoor enters passive backdoor mode and waits for an activation message,” XLab said. “When the Backdoor Type value is not 1, MystRodX enters active backdoor mode and establishes communication with the C2 specified in the configuration, waiting to execute the received commands.”

The term “backdoor”refers to a hidden or unauthorized method of accessing a system, software, or network. It is usually used in the context of cybersecurity and hacking and has a negative connotation, as it allows the bypassing of normal authentication and security procedures.

Backdoors may be intentionally installed by developers for maintenance or access recovery purposes, but they are often used maliciously by attackers who exploit system vulnerabilities or embed malicious code (malware) to gain remote control. One example is the remote access Trojan (RAT), a type of malware that gives the attacker full access to the victim's system.

See also: Hackers install backdoor in WordPress Mu-Plugins

Researchers warn about MystRodX Backdoor
Researchers warn about MystRodX Backdoor

Backdoors have even been found in commercial products or hardware, raising concerns about privacy and national security. A famous example is the controversy surrounding allegations of backdoors in telecommunications equipment.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS