• Contact Us
  • Login
Upgrade
Tech News Hero
Advertisement
  • Home
  • News
  • Gadgets
  • Social
  • Gaming
  • Mobile
  • PC
  • Internet
  • Security
  • Apps
No Result
View All Result
  • Home
  • News
  • Gadgets
  • Social
  • Gaming
  • Mobile
  • PC
  • Internet
  • Security
  • Apps
No Result
View All Result
Tech News Hero
No Result
View All Result
Home Security

Platinum APT’s new Titanium backdoor mimics popular PC software to stay hidden

by technewshero
November 8, 2019
in Security
0
Share on FacebookShare on Twitter
New variant of trojan malware puts your personal information at risk
NanoCore RAT can steal passwords, payment details, and secretly record audio and video of Windows users.

The Platinum advanced persistent threat (APT) cyberattack group has developed a new backdoor with interesting concealment techniques. 

Platinum has been tracked since 2012 and generally targets government, military, and political targets across the APAC region. 

In recent years, the hacking group has become linked to the use of novel attack techniques, such as the abuse of a now-deprecated Windows feature called hotpatching and fileless code deployment, as well as steganography to hide Powershell and exploit code in plain text. 

See also: Facebook enjoys rare court win over privacy breach, investor claims

A past backdoor connected to Platinum uses text steganography to hide command-and-control (C2) communication. Now, the APT appears to have added a new backdoor, dubbed Titanium, to its arsenal. 

Named after a password to one of its archives, Titanium “hides at every step by mimicking common software” including protection-related, sound driver software, and video creation tools, according to Kaspersky researchers. 

In attack chains tracked by the team, Platinum will deploy Titanium as the last stage of infection. 

CNET: Lasers can seemingly hack Alexa, Google Home and Siri

Each example found involved the use of an exploit for executing code as a system-level user and shellcode to download an additional downloader. Platinum targets winlogon.exe but Kaspersky does not know how the injection occurs. 

The deployment of an SFX archive containing a Windows task installation script is then underway. This password-protected, encrypted archive is downloaded via BITS Downloader, and its main task is to install a Windows task to maintain persistence. 

The attack chain will then involve the launch of a further archive containing an installer, a COM object DLL, and the Titanium backdoor itself. Titanium’s paths all masquerade as a common software installer, such as for DVD creation software or as an audio driver, and the backdoor will then seek a connection to its C2 once executed. 

To establish a connection with its C2, Titanium will send a base64-encoded request containing a system ID, computer name, and the hard disk’s serial number. 

TechRepublic: You’ve got malware: Malicious actors are waiting in your inbox

When pinging the C2 for commands, the malware will be answered with PNG files containing steganographically hidden data, containing directions for the malicious code. Commands may include reading system files, deleting content, dropping and executing files, running command line queries and sending the results to the C2, and update configuration requests. 

Kaspersky is unaware of any active campaigns, at present.

“The Titanium APT has a very complicated infiltration scheme. It involves numerous steps and requires good coordination between all of them. In addition, none of the files in the file system can be detected as malicious due to the use of encryption and fileless technologies,” the researchers say. “One other feature that makes detection harder is the mimicking of well-known software.”

Previous Post

iOS 13.2.2 is here and it’ll fix that annoying bug the last update caused

Next Post

WhatsApp for iPhone’s Recent Update Drastically Impacting Battery Life, User Reports

technewshero

technewshero

Related Posts

2020 Shows the Danger of a Decapitated Cyber Regime
Security

2020 Shows the Danger of a Decapitated Cyber Regime

by technewshero
January 13, 2021
A ‘Bulletproof’ Criminal VPN Was Taken Down in a Global Sting
Security

A ‘Bulletproof’ Criminal VPN Was Taken Down in a Global Sting

by technewshero
January 14, 2021
The Worst Hacks of 2020, a Surreal Pandemic Year
Security

The Worst Hacks of 2020, a Surreal Pandemic Year

by technewshero
January 15, 2021
How to Understand the Russia Hack Fallout
Security

How to Understand the Russia Hack Fallout

by technewshero
December 22, 2020
A Massive Fraud Operation Stole Millions From Online Bank Accounts
Security

A Massive Fraud Operation Stole Millions From Online Bank Accounts

by technewshero
December 21, 2020
Next Post

WhatsApp for iPhone's Recent Update Drastically Impacting Battery Life, User Reports

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Most Popular

Amazon Showroom gives you a glimpse of your virtual dream home

August 29, 2019

Now TV’s Game of Thrones offer is ending soon if you’re planning a mega binge

May 19, 2019
How to buy a new iPhone 11 and 11 Pro right now

How to buy a new iPhone 11 and 11 Pro right now

January 14, 2021

Browse by Category

  • Apps
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • News
  • PC & Laptops
  • Security
  • Social
Tech News Hero

© 2020 Tech News Hero.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© 2020 Tech News Hero.

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?