Possible Pakistan-Linked Backdoor Targets Afghanistan
Analysis details a backdoor delivered through DLL side-loading, with Afghan government targeting clues, persistence via a Windows Run key, and C2 at 185.235.137[.]35:9000.
Analysis details a backdoor delivered through DLL side-loading, with Afghan government targeting clues, persistence via a Windows Run key, and C2 at 185.235.137[.]35:9000.
Analysis of a malware sample describes a CommuniGate Pro-themed LNK lure, DLL side-loading through calibre.exe, persistence, and a stager that contacts a command-and-control server to retrieve and execute additional payloads.
Researchers analyzed a low-detection, statically linked Linux backdoor delivered as a PNG-named ELF. It profiles hosts, communicates with C2, executes commands, transfers files, and supports reverse tunnels; later analysis noted similarities to Adaptix Agent.
A technical analysis details an ELF backdoor that appears to target iKuai routers, beaconing to a command-and-control server and supporting shell commands, file exfiltration, and payload execution.
A researcher analyzed an ISO containing a .NET dropper and a previously unseen RAT dubbed PulseRAT. The RAT uses Google Sheets for command and control, collects system information, and executes attacker-supplied PowerShell commands.