Skip to main content

Malware Framework - AfterMidnight and Assassin

Documentation pertaining to two malware platforms named AfterMIdnight (AM) and Assassin was recently released. The frameworks implement backdoor features which can allow an attacker to take control of affected systems.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Documentation pertaining to two malware platforms named AfterMIdnight (AM) and Assassin was recently released. The frameworks implement backdoor features which can allow an attacker to take control of affected systems.

Affected platforms

The following platforms are known to be affected:

Threat details

AfterMidnight

According to the documentation, the payload disguises itself as a self persisting Windows Dynamic Link Library (DLL) file and executes small payloads named 'gremlins' through a HTTP based Listening Port (LP), similar to a Command and Control (C2) server.

Once AM is installed on a target host it will call back to the configured LP checking for gremlins to execute. If gremlins are present, AM will download and store all necessary components before loading the Gremlins into memory.

The documentation states that gremlins are payloads which can subvert functionality of targeted software, provide basic survey and data exfiltration and also provides internal services for other gremlins.

AM affects both Windows and Linux based operating systems and will only uninstall when one of the following conditions are met:

  • The configured uninstall date is reached
  • The configured 'dead man' timer expires
  • The configured kill file is seen to exist on disk
  • The Midnight Core file is not present at startup

Assassin

The documentation describes Assassin as an automated implant. It is similar to AfterMidnight (AM) in that it provides a simple collection platform on remote computers running Microsoft Windows operating systems.

Once installed on a target system, Assassin runs within a Windows service process and periodically beacons out to a Command and Control (C2) server, similar to how AfterMidnight communicates.

According to the user guide, Assassin includes five types of implant executables; DLL, EXE, Service DLL, ICE DLL and Pernicious DLL.

Similar to AM, Assassin can be scheduled to uninstall at a specific time or date, or if it passes a specific failure threshold.


Remediation steps

Type Step
  • Never click on links or open email attachments from untrusted sources.
  • Monitor for anomalous activity in network and proxy logs.
  • In general, make sure that patches are applied as soon as possible once released.
  • Make sure that cyber awareness training is provided and kept up-to-date.

Last edited: 17 February 2020 11:34 am