Research

More on Backdoor.Win32.Breplibot.b

We’ve been analysing the backdoor program which uses the Sony rootkit technology.

Trend Micro has told us that the backdoor was mass mailed using spamming technologies. The message sent was as follows:

Message subject:

Requesting Photo Approval

Attachment name:

article_december_3621.exe

Message body:

Hello,

Your photograph was forwarded to us as part of an article we are publishing for our December edition of Total Business Monthly. Can you check over the format and get back to us with your approval or any changes? If the picture is not to your liking then please send a preferred one. We have attached the photo with the article here.

Kind regards,
Jamie Andrews
Editor
www.TotalBusiness.co.uk
**********************************************
The Professional Development Institute
**********************************************

Breplibot.b is 10240 bytes in size, and packed using UPX.

When launching, the backdoor copies itself to the Windows system directory as $SYS$DRV.EXE. Using this name makes it possible for the rootkit technology used by Sony to hide the activity of the malicious program. Of course, the backdoor’s activity will only be hidden if the ‘Sony rootkit’ has been installed on your computer.

Once launched, the backdoor creates the following system registry key:

[HKEY_LOCAL_MACHINE] “WkbpsevaXImgvkwkbpXSmj`kswXGqvvajpRavwmkjXVqj”=”$SYS$DRV.EXE”

More on Backdoor.Win32.Breplibot.b

Your email address will not be published.

 

Reports

The SessionManager IIS backdoor

In early 2022, we investigated an IIS backdoor called SessionManager. It has been used against NGOs, government, military and industrial organizations in Africa, South America, Asia, Europe, Russia and the Middle East.

APT ToddyCat

ToddyCat is a relatively new APT actor responsible for multiple sets of attacks against high-profile entities in Europe and Asia. Its main distinctive signs are two formerly unknown tools that we call ‘Samurai backdoor’ and ‘Ninja Trojan’.

WinDealer dealing on the side

We have discovered that malware dubbed WinDealer, spread by Chinese-speaking APT actor LuoYu, has an ability to perform intrusions through a man-on-the-side attack.

APT trends report Q1 2022

This is our latest summary of advanced persistent threat (APT) activity, focusing on events that we observed during Q1 2022.

Subscribe to our weekly e-mails

The hottest research right in your inbox