216.73.216.233

RansomHub Affiliate leverages Python-based backdoor

· Published 16/01/2025 17:05 · Modified 16/01/2025 18:51

Export JSON

Essential information

Published
16/01/2025 17:05
Modified
16/01/2025 18:51
Tags
2025-01-16 c2 infrastructure lateral movement obfuscation python backdoor ransomhub ransomware reverse proxy socgholish socks5
Related entities
6 observables, 1 intrusion sets (apt), 10 techniques (mitre), 2 malware

Description

A threat actor utilized a Python-based backdoor to maintain access to compromised endpoints, later deploying encryptors across the impacted network. The malware, an updated version of a previously documented backdoor, features , deployment via RDP, and unique indicators of compromise. Initial access was linked to (FakeUpdate), followed by the installation of Python and the backdoor on multiple systems. The script functions as a , establishing a -like tunnel for . The code's polished nature suggests possible AI-assisted creation. The C2 process involves multiple steps, including hardcoded IP addresses and port assignments. This incident highlights affiliates' continued use of Python backdoors for persistence and evasion, as well as the potential adoption of AI-assisted code in malware development.

External references