Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le novembre 12, 2017, 14:00:25

Titre: [Trend]REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography
Posté par: igor51 le novembre 12, 2017, 14:00:25
REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography

REDBALDKNIGHT, also known as BRONZE BUTLER and Tick, is a cyberespionage group known to target Japanese organizations such as government agencies (including defense) as well as those in biotechnology, electronics manufacturing, and industrial chemistry. Their campaigns employ the Daserf backdoor (detected by Trend Micro as BKDR_DASERF, otherwise known as Muirim and Nioupale) that has four main capabilities: execute shell commands, download and upload data, take screenshots, and log keystrokes.


Our recent telemetry, however, indicates that variants of Daserf were not only used to spy on and steal from Japanese and South Korean targets, but also against Russian, Singaporean, and Chinese enterprises. We also found various versions of Daserf that employ different techniques and use steganography—embedding codes in unexpected mediums or locations (i.e., images)—to conceal themselves better.


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography


Source: REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography (http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/PV3yQJrJXAQ/)