216.73.217.22

A PAINFUL QUICKHEAL

· Published 16/12/2024 13:03 · Modified 16/12/2024 14:33

Export JSON

Essential information

Published
16/12/2024 13:03
Modified
16/12/2024 14:33
Tags
2024-12-16 nomad panda pla quickheal redfoxtrot vmprotect
Related entities
1 intrusion sets (apt), 11 techniques (mitre), 1 malware, 5 others

Description

This report analyzes a malware sample associated with the Chinese -linked Needleminer group. The 32-bit DLL, protected by , targets the telecom sector and was compiled in April 2022. It can steal credentials from Firefox and Internet Explorer browsers. The malware communicates with a C2 server using HTTP and attempts to establish connections via proxy. It employs various obfuscation techniques, including renaming cmd.exe and using a custom API resolver. The attackers' infrastructure, spanning multiple years and campaigns, shows poor operational security but targets diverse sectors and countries, including India, South Korea, and potentially the Middle East.

External references