Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deployment of a backdoor (which we dubbed CCoreDoor, and BitDefender has designated as EtherealGh0st) to move laterally, establish external C2 communications, perform discovery, and dump credentials.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Cluster Bravo activity was primarily focused on using valid accounts to spread laterally throughout the network... there were some instances of the clusters using the same credentials, such as the actors in Cluster Alpha and Cluster Bravo using the same insecure administrator account.
wmic /node:"172.27.<redacted>" /user:"<redacted>" /password:"<redacted>" process call create "c:\programdata\vmnat\vmtools\vmnat.exe"
The actor created several scheduled tasks throughout the intrusion to execute the renamed mscorsvw.exe binary and sideload the malicious mscorsvc.dll (CCoreDoor) onto different machines.
Using WScript to run a vbscript (vbs | 3.vbs) that executed the backdoor on various systems
MDR launched the hunt after the discovery of a DLL sideloading technique that exploited VMNat.exe, a VMware component... The Crimson Palace campaign included over 15 distinct DLL sideloading scenarios... Cluster Alpha activity included multiple sideloading attempts to deploy various malware... Cluster Bravo used renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment.
The actor created several scheduled tasks throughout the intrusion to execute the renamed mscorsvw.exe binary and sideload the malicious mscorsvc.dll (CCoreDoor) onto different machines.
Cluster Bravo activity was primarily focused on using valid accounts to spread laterally throughout the network... there were some instances of the clusters using the same credentials, such as the actors in Cluster Alpha and Cluster Bravo using the same insecure administrator account.
The actor created several scheduled tasks throughout the intrusion to execute the renamed mscorsvw.exe binary and sideload the malicious mscorsvc.dll (CCoreDoor) onto different machines.
Cluster Bravo activity was primarily focused on using valid accounts to spread laterally throughout the network... there were some instances of the clusters using the same credentials, such as the actors in Cluster Alpha and Cluster Bravo using the same insecure administrator account.
Use of renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment and move laterally... Sophos observed the PhantomNet backdoor implant (sslwnd64.exe)...
Cluster Bravo activity was primarily focused on using valid accounts to spread laterally throughout the network... there were some instances of the clusters using the same credentials, such as the actors in Cluster Alpha and Cluster Bravo using the same insecure administrator account.
The second thread aims to ensure the backdoor activity is hidden by rapidly enumerating all windows every 100 milliseconds and hiding the one that belongs to itself.
MDR launched the hunt after the discovery of a DLL sideloading technique that exploited VMNat.exe, a VMware component... The Crimson Palace campaign included over 15 distinct DLL sideloading scenarios... Cluster Alpha activity included multiple sideloading attempts to deploy various malware... Cluster Bravo used renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment.
The CCoreDoor backdoor deployed in Cluster Bravo executed various discovery commands, including ... ipconfig /all ... tracert -d -h 3 <IP>, netstat -ano
dnscmd . /EnumRecords <domain> ... dsquery server ... ping sweeps of over 1800 machines.
The CCoreDoor backdoor deployed in Cluster Bravo executed various discovery commands, including whoami... query u
Cluster Bravo activity was primarily focused on using valid accounts to spread laterally throughout the network... Use of renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment and move laterally from the beachhead host to other remote servers... discovery and lateral movement efforts continued over the next several months.
the overall goal behind the campaign was to maintain access to the target network for cyberespionage... deploying various malware implants for command-and control (C2) communications... Use of multiple persistent C2 channels including Merlin Agent, PhantomNet backdoor, RUDEBIRD malware, EAGERBEE malware, and PowHeartBeat backdoor... Deployment of several samples of... PocoProxy for persistent C2 communications.
setDesktopMonitorHook function, which establishes communications with the domain cloud.keepasses[.]com ... PowHeartBeat backdoor ... connect to msudapis[.]info over port 443
High prioritization of evasive tactics and tools: ... overwriting ntdll.dll in memory to unhook the Sophos AV agent process from the kernel, abusing AV software for sideloading... Deployment of new EAGERBEE malware variants with updated capability of modifying packets to disrupt security agent network communications.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A simple backdoor sideloaded via mscorsvw.exe that supports lateral movement, discovery, LSASS dumping, and external C2 communications.
A novel backdoor used for lateral movement, external command-and-control, discovery, and credential dumping.
Backdoor used for lateral movement, external C2, discovery, and credential dumping; overlaps with BitDefender’s EtherealGh0st (CCore library, similar command set, and C2 domain overlap).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.