Unpacking the spyware disguised as antivirus

JMH

Emeritus, Contributor
Joined
Apr 2, 2012
Posts
7,197
Recently we got access to several elements of the espionage toolkit that has been captured attacking Vietnamese institutions. During the operation, the malware was used to dox 400,000 members of Vietnam Airlines.

The payload, distributed disguised as antivirus, is a variant of Korplug RAT (aka PlugX) – a spyware with former associations with Chinese APT groups, and known from targeted attacks at important institutions of various countries.

In this article we will describe the process of extracting the final payload out of it’s cover.

Analyzed samples

Set #1:


Execution flow:


McAfee.exe -> McUtil.dll -> McUtil.dll.mc -> payload (DLL)
https://blog.malwarebytes.com/threat-analysis/2016/08/unpacking-the-spyware-disguised-as-antivirus/
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top