216.73.216.6

A Cereal Offender: Analyzing the CORNFLAKE.V3 Backdoor

· Published 21/08/2025 02:20 · Modified 21/08/2025 12:23

Export JSON

Essential information

Published
21/08/2025 02:20
Modified
21/08/2025 12:23
Tags
2025-08-21 backdoor clickfix cornflake.v3 kerberoasting node.js php windytwist.sea
Related entities
1 intrusion sets (apt), 2 malware

Description

This analysis details a campaign involving two threat groups, UNC5518 and UNC5774, deploying the . UNC5518 compromises legitimate websites to serve fake CAPTCHA pages, luring visitors to execute a downloader script. UNC5774 then uses this access to deploy , a sophisticated with variants in JavaScript and . The malware collects system information, establishes persistence, and can execute various payloads including shell commands, executables, and DLLs. It communicates with command and control servers using HTTP and can abuse Cloudflare Tunnels for traffic proxying. The campaign also involves active directory reconnaissance and credential harvesting attempts via .

External references