216.73.216.6

Malware Analysis: A Kernel Land Rootkit Loader for FK_Undead

· Published 11/12/2024 04:36 · Modified 11/12/2024 11:03

Export JSON

Essential information

Published
11/12/2024 04:36
Modified
11/12/2024 11:03
Tags
2024-12-11 deaddrop driver evasion fk_undead kernel proxy rootkit vmprotect windows
Related entities
20 observables, 1 intrusion sets (apt), 1 malware

Description

This analysis delves into a loader for the malware family, known for intercepting user network traffic through manipulation. The loader, signed with a valid Microsoft certificate, installs itself as a system service and employs various techniques. It downloads and decrypts a payload, which is another signed protected by . The checks for security tools, virtual machine environments, and implements notify routines to hide from detection. It uses deaddrops to retrieve URLs for downloading the payload, which is then decrypted and installed as a separate service.

External references