Possible Pakistan-Linked Backdoor Targets Afghanistan

· Original article ↗

Summary

Analysis details a backdoor delivered through DLL side-loading, with Afghan government targeting clues, persistence via a Windows Run key, and C2 at 185.235.137[.]35:9000.

Key points

  • A ZIP uploaded to VirusTotal from Afghanistan contained a renamed legitimate Windows executable and malicious dgxi.dll, which the executable side-loads.
  • The malware copies itself and the executable to %AppData%\Microsoft\ApplicationHost\ and persists through the current user's Windows Run key.
  • Its decoy PDF is in Pashto and contains names, job titles, salaries, departments, and phone numbers, suggesting a government-related lure.
  • The backdoor connects to 185.235.137[.]35:9000 and sends a beacon with the victim machine's ID, name, and Windows version.
  • Supported commands include file listing, upload and download, file deletion, process execution and control, and an interactive command shell.
  • It uses debugger and analysis-tool checks, timing and integrity checks, and XOR-encrypted C2 configuration.
  • The article provides these indicators: C2 185.235.137[.]35:9000, dgxi.dll SHA-256 a6ceacac670b88e8a8ec9ff5da6a77d9f1c896d6479b2dadb700474a8c408f80, and a ZIP hash listed in the source.

Article Details

Attack Vectors
  • A ZIP file uploaded from Afghanistan contained a legitimate Windows executable renamed to resemble recruitment information and a malicious dgxi.dll that the executable side-loads. The filename and upload origin suggest, but do not confirm, targeting of an Afghanistan government agency.
  • The backdoor copies the executable and DLL to %AppData%\Microsoft\ApplicationHost\ and establishes persistence through HKCU\Software\Microsoft\Windows\CurrentVersion\Run.
  • The DLL checks for debuggers and analysis tools, decrypts its C2 configuration, and connects to the C2. Its commands support system profiling, file transfer, process execution, and an interactive shell.
Defensive Notes
  • The DLL checks for CheckRemoteDebuggerPresent(), OutputDebugStringA() timing, and the presence of named analysis tools.
  • The C2 configuration is XOR-encrypted with the key thisscert23$SecretKey206.
  • C2 packets use the magic number 0xDEADBEEF; communication is mostly JSON, with some commands using JSON headers followed by binary data.

Indicators of compromise

TypeIndicatorContext
IPV4185[.]235[.]137[.]35Backdoor C2 address obtained by decrypting its configuration; the reported port is 9000.
SHA256a6ceacda670b88e8a8ec9ff5da6a77d9f1c896d6479b2dadb700474a8c408f80SHA-256 listed for the malicious side-loaded dgxi.dll.
SHA256d69d27a94c78889fc8694e13c122438125eb3d3e6023e0624b3137c7f982a852SHA-256 listed for the ZIP file containing the malicious DLL and renamed executable.

MITRE ATT&CK

Vendors

Products

Tools

Countries

Industries

Related Articles