FINALDRAFT, also known as Squidoor, is a modular cross-platform remote-access backdoor associated with the espionage-focused REF7707 activity cluster, also tracked as Jewelbug, Ink Dragon, CL-STA-0049, and Earth Alux. It has targeted government, telecommunications, and other organizations in South America, Southeast Asia, and Europe. The malware runs on Windows and Linux and is commonly deployed by the PATHLOADER and GUIDLOADER in-memory loaders.
Windows variants are 64-bit C++ implants that use Microsoft Graph API access and Outlook draft messages for command-and-control. They encrypt and encode tasking and responses, poll mailbox drafts for operator commands, and remove retrieved command messages. FINALDRAFT supports host and process discovery, file operations, data collection and exfiltration, process execution, process injection, TCP/UDP and named-pipe proxying, and firewall-rule management for listener functionality. It can inject into existing or hidden newly created processes and load reflectively injected modules for network enumeration, in-memory PowerShell execution with AMSI and ETW bypasses, and Pass-the-Hash activity.
Linux ELF variants provide host and network discovery, shell-command execution, self-deletion, and multiple command-and-control transports, including web protocols, DNS, ICMP, TCP, UDP, and Outlook-based channels. FINALDRAFT's use of legitimate Microsoft cloud services and internal traffic proxying can reduce the effectiveness of network-based detection and support covert post-exploitation operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FINALDRAFT is a well-engineered, full-featured remote administration tool with the ability to accept add-on modules that extend functionality and proxy network traffic internally by multiple means.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence was achieved using a Scheduled Task that invoked the renamed CDB.exe debugger and the weaponized INI file every minute as SYSTEM.
“Psloader.x64.dll ... allows the operator to execute PowerShell commands without invoking the powershell.exe binary.”
Persistence was achieved using a Scheduled Task that invoked the renamed CDB.exe debugger and the weaponized INI file every minute as SYSTEM.
Persistence was achieved using a Scheduled Task that invoked the renamed CDB.exe debugger and the weaponized INI file every minute as SYSTEM.
The rule includes byte sequences named "$seq_derive_encryption_key" and "$seq_decrypt_configuration."
“the target process is either an executable path provided as a parameter ... or defaults to mspaint.exe or conhost.exe as a fallback.”
“The domains purposely typosquat real known vendors, CheckPoint and Fortinet” and “VMSphere (VMware vSphere).”
The FinalDraft YARA rule contains potential injection-target paths for "%c:\Windows\SysWOW64\mspaint.exe", "%c:\Windows\System32\mspaint.exe", "%c:\Windows\SysWOW64\conhost.exe", and "%c:\Windows\System32\conhost.exe".
“The process injection procedure is basic and based on VirtualAllocEx, WriteProcessMemory, and RtlCreateUserThread API.”
“For the file deletion functionality, FINALDRAFT prevents file recovery by overwriting file data with zeros before deleting them.”
Both PATHLOADER and GUIDLOADER are used to download and execute encrypted shellcodes in memory.
fontdrvhost.exe is a renamed version of the Windows-signed debugger CDB.exe. Abuse of this binary allowed our attackers to execute malicious shellcode delivered in the config.ini file under the guise of trusted binaries.
“The decryption key is derived either from the Windows product ID (HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId).”
“ipconfig.x64.dll ... [retrieves] networking information using Windows API’s (GetAdaptersAddresses, GetAdaptersInfo, GetNetworkParams) and reading the Windows registry.”
“ListActiveTcpUdpConnections” and “List of active network connections” are collected by the ELF variant.
“ListRunningProcesses” is a FINALDRAFT command, and gathered system data includes “details about running processes.”
The malware supported multiple covert command-and-control (C2) methods, including Microsoft Graph/Outlook APIs, DNS tunnelling and ICMP tunnelling.
Once the initial execution and check-in have been completed, all further communication proceeds through legitimate Microsoft infrastructure (graph.microsoft[.]com).
The malware supported multiple covert command-and-control (C2) methods, including Microsoft Graph/Outlook APIs, DNS tunnelling and ICMP tunnelling.
“FINALDRAFT offers various methods of proxying data to C2, including UDP and TCP listeners, and a named pipe client.”
"REF7707, a threat campaign involving the FINALDRAFT, PATHLOADER, and GUIDLOADER malware families, provides details about how an espionage-motivated threat evaded defenses using Microsoft’s GraphAPI for C2."
Google's Firebase service, Pastebin, and a Southeast Asian University are third-party services used to host the encrypted payload for the loaders (PATHLOADER and GUIDLOADER) to download and decrypt the last stage of FINALDRAFT.
FINALDRAFT ... command and control using ... abuse of Microsoft's Graph API. Once the initial execution and check-in have been completed, all further communication proceeds through legitimate Microsoft infrastructure.
“COutlookTrans class ... abuses the Outlook mail service via the Microsoft Graph API.”
REF7707 used Microsoft's certutil application to download files from a remote server and save them locally.
“hooks ... AmsiScanBuffer APIs, forcing them to always return 0 ... bypasses anti-malware scans.”
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Implant/backdoor that uses Microsoft Graph API for C2; referenced as similar to NANOREMOTE.
Bespoke malware providing remote access; uses Microsoft Graph API for C2/operations; used for espionage against a South American foreign ministry and other entities.
Backdoor used for data exfiltration and lateral movement in victim environments.
Malware used in targeted attacks against government and telecom entities, specific functionality not detailed in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.