Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this blog post we’re presenting a detailed analysis of 2 malicious files (a backdoor known as “Travelnet”) linked to an APT (Advanced Persistent Threat) actor called APT21. The first file is a dropper used to register a malicious DLL (NetTraveler trojan) as a service.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The first file is a dropper used to register a malicious DLL (NetTraveler trojan) as a service... A new service called “FastUserSwitchingCompatibility” is created using CreateServiceA API function... A new key called “Parameters” is created... This will be used to register a malicious DLL as a service.
the attacker’s purpose is to steal “explorer.exe” process’ token by calling OpenProcessToken... and then it uses ImpersonateLoggedOnUser function to impersonate the security context of a user.
The first file is a dropper used to register a malicious DLL (NetTraveler trojan) as a service... A new service called “FastUserSwitchingCompatibility” is created using CreateServiceA API function... A new key called “Parameters” is created... This will be used to register a malicious DLL as a service.
A new service called “FastUserSwitchingCompatibility” is created... which tries to impersonate the legitimate service... Attackers will try to impersonate/use legitimate system binaries or libraries on the host to hide malicious activity.
If all methods fail, the infection will stop and the following operations are performed (self-deleting malware)... registry keys are deleted... The following files are deleted as well...
The main purpose of the trojan is to gather information about the environment... the list of processes... A list of processes is retrieved using Process32First and Process32Next APIs...
The main purpose of the trojan is to gather information about the environment such as user name, host name, IP address of the host, Windows OS version, different configurations of the CPU, information about memory consumption...
The file will enumerate all files and directories from the “C:\” drive... all information described will be stored in a new file called “C:\Windows\SysWOW64\enumfs.ini”... The operation applied to “C:\” drive is recursive...
The malicious process is interested in .doc, .docx, .xls, .xlsx, .txt, .rtf, .pdf files on disk and also on USB drives...
The malicious process is interested in .doc, .docx, .xls, .xlsx, .txt, .rtf, .pdf files... also on... network shares in order to exfiltrate them.
The data is compressed using a custom Lempel-Ziv-based algorithm and encoded with a modified Base64 algorithm before it will be exfiltrated to the Command and Control server.
The user agent used in the network communications is always set to “Mozilla/4.0 (compatible; MSIE 6.0)”... The encoded data is exfiltrated via a GET request to vipmailru[.]com (C2 server).
the attacker verifies if he’s able to connect to the same URL using the proxy settings he found in the registry... the malicious process modifies the config_t.dat file by setting UP=1... and then PS (proxy server), PP (proxy port), PU (proxy user), PW (proxy password) are set according to the settings found.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.