216.73.217.22

MoonWalk

· Published 12/07/2024 16:11 · Modified 12/07/2024 16:20

Export JSON

Essential information

Published
12/07/2024 16:11
Modified
12/07/2024 16:20
Tags
2024-07-12 backdoor dodgebox evasion googledrive moonwalk nationstate windows
Related entities
3 observables, 1 intrusion sets (apt), 7 techniques (mitre), 2 malware

Description

This blog post examines , a new employed by APT41, a China-based threat actor known for campaigns in Southeast Asia. utilizes numerous techniques, including DLL hollowing, call stack spoofing, and the abuse of Fibers to evade security solutions. It also leverages Google Drive as a command-and-control channel, blending in with legitimate network traffic. 's modular design allows for easy capability updates and customization for different scenarios.

External references