LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company
#1
Information 
[Image: 180907-LuckyMouse-1.png]

What happened?
Since March 2018 we have discovered several infections where a previously unknown Trojan was injected into the lsass.exe system process memory. These implants were injected by the digitally signed 32- and 64-bit network filtering driver NDISProxy. Interestingly, this driver is signed with a digital certificate that belongs to Chinese company LeagSoft, a developer of information security software based in Shenzhen, Guangdong. We informed the company about the issue via CN-CERT.
The campaign described in this report was active immediately prior to Central Asian high-level meeting and we suppose that actor behind still follows regional political agenda.

Which malicious modules are used?
The malware consists of three different modules:
  • A custom C++ installer that decrypts and drops the driver file in the corresponding system directory, creates a Windows autorun service for driver persistence and adds the encrypted in-memory Trojan to the system registry.
  • A network filtering driver (NDISProxy) that decrypts and injects the Trojan into memory and filters port 3389 (Remote Desktop Protocol, RDP) traffic in order to insert the Trojan’s C2 communications into it.
  • A last-stage C++ Trojan acting as HTTPS server that works together with the driver. It waits passively for communications from its C2, with two possible communication channels via ports 3389 and 443.

[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread:
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
XYplorer
What's new in Rele...Kool — 15:21
Free Download Manager 6.30.0.6459
Changes in 6.30.0....harlan4096 — 13:51
AMD introduces Ryzen PRO 9000 series, Ry...
AMD launches first...harlan4096 — 13:49
Ashampoo Home Design 10 FREE!
Jaki jest kodCygi — 09:31
AMD launches EPYC 4005 Embedded, Zen5 CP...
AMD has new EPYC 4...harlan4096 — 08:54

[-]
Birthdays
Today's Birthdays
avatar (45)ThomasLYDAY
avatar (40)upakoExapy
Upcoming Birthdays
avatar (38)fapedDow
avatar (48)pohudidere
avatar (38)eqiduseb
avatar (49)skepwHug
avatar (38)RicardoGoase
avatar (43)Denpokhew
avatar (35)azidony
avatar (40)maskbSleew

[-]
Online Staff
There are no staff members currently online.

>