Auteur Sujet: [FireEye]To SDB, Or Not To SDB: FIN7 Leveraging Shim Databases for Persistence  (Lu 3248 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
To SDB, Or Not To SDB: FIN7 Leveraging Shim Databases for Persistence

[html]

In 2017, Mandiant responded to multiple incidents we attribute to
  FIN7, a financially motivated threat group associated with malicious
  operations dating back to 2015. Throughout the various environments,
  FIN7 leveraged the CARBANAK backdoor, which this group has used in
  previous operations.


 

A unique aspect of the incidents was how the group installed the
  CARBANAK backdoor for persistent access. Mandiant identified that the
  group leveraged an application shim database to achieve persistence on
  systems in multiple environments. The shim injected a malicious
  in-memory patch into the Services Control Manager (“services.exe”)
  process, and then spawned a CARBANAK backdoor process.


 

Mandiant identified that FIN7 also used this technique to install a
  payment card harvesting utility for persistent access. This was a
  departure from FIN7’s previous approach of installing a malicious
  Windows service for process injection and persistent access.


 

Application Compatibility Shims Background


 

According to Microsoft, an application compatibility shim is
  a small library that transparently intercepts an API (via hooking),     href="https://blogs.technet.microsoft.com/askperf/2011/06/17/demystifying-shims-or-using-the-app-compat-toolkit-to-make-your-old-stuff-work-with-your-new-stuff/">changes
    the parameters passed, handles the operation itself, or
  redirects the operation elsewhere, such as additional code stored on a
  system.


Tags: