HomeSecuritySkeleton Key Malware Active for Two Years

Skeleton Key Malware Active for Two Years

The Skeleton Key malware managed to stay “hidden” for the past two years, but researchers at Dell SecureWorks discovered it on a client’s network.

Skeleton Key Malware

The threat has been used by attackers to bypass authentication on Active Directory with single-factor authentication security policies. This allows them to log in to the system as a legitimate user, but with a password of their choosing.

Symantec conducted its own analysis on a sample of the malware and identified a connection to the Winnti backdoor , which is used in multiple targeted attacks against companies around the world .

Kaspersky claims that the backdoor is operated by attackers who specialize in breaching the networks of companies in the video game industry and has the potential to steal source code and digital certificates.

Gavin Gorman from Symantec says of Skeleton Key (detected as Trojan.Skelky) that, over the past two years, the malware has evolved and new variants have emerged.

The first traces of its activity were recorded in January 2013 and it had not appeared until November of the same year. Since then, attackers have used it frequently as four variants have emerged.

" Symantec has detected Skeleton Key malware on compromised computers at five organizations, with offices in the United States and Vietnam. The exact nature and names of the affected organizations are unknown to Symantec," Gorman in a blog post from Thursday.

The connection between Skeleton Key and Winnti was made based on the fact that the attackers used the same password in three different variants of the malware, indicating that a single group is behind it.

Other threats found on two of the systems compromised by the Skeleton Keyinclude a variant of the Winnti backdoor and a dropper for it. Since both threats were detected on the same systems, it can be concluded that they can be used in combination.

Symantec has not found evidence to suggest that multiple hacker groups used this malware, but it does not rule out the possibility.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS