216.73.217.22

Njrat Campaign Using Microsoft Dev Tunnels

· Published 27/02/2025 14:19 · Modified 27/02/2025 15:48

Export JSON

Essential information

Published
27/02/2025 14:19
Modified
27/02/2025 15:48
Tags
2025-02-27 c2 communication malware campaign microsoft dev tunnels njrat usb propagation
Related entities
6 observables, 8 techniques (mitre), 4 malware

Description

A new has been detected utilizing Microsoft's dev tunnels service for command and control (C2) communication. This service, designed for developers to securely expose local services to the internet, is being exploited by the malware to establish connections with C2 servers. Two samples were identified with different dev tunnel URLs but identical Import Hashes. The malware sends status updates to the C2 server and can potentially propagate through USB devices. A configuration file extracted from one sample reveals details about the C2 server, ports, and botnet name. The article suggests monitoring DNS logs for 'devtunnels.ms' as a defensive measure against this threat.

External references