216.73.217.98

Unmasking the Shadow of PoisonPlug's Obfuscator

· Published 29/01/2025 01:42 · Modified 29/01/2025 12:02

Export JSON

Essential information

Published
29/01/2025 01:42
Modified
29/01/2025 12:02
Tags
2025-01-29 cyber espionage poisonplug poisonplug.deed poisonplug.shadow scatterbee scatterbrain
Related entities
2 observables, 1 intrusion sets (apt), 20 techniques (mitre), 2 malware

Description

Since 2022, operations utilizing have been tracked, employing a custom obfuscating compiler called . This evolved version of targets entities in Europe and Asia Pacific. , a variant of the modular backdoor, uses advanced obfuscation techniques to evade detection. The blog post details the analysis of , including its modes of operation, protection components, and the development of a deobfuscator. It explains the process of CFG recovery, import restoration, and binary reconstruction. The research provides insights into combating sophisticated obfuscation techniques and contributes to enhancing cybersecurity defenses against evolving threats.

External references