SYSCON Backdoor Uses FTP as a C2 Channel
A botnet has been found that uses an unusual method for its bots to communicate to a Command and Control (C2) server. A machine infected with the "SYSCON" backdoor has been identified to use an FTP server for communication as well as a C2 server
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A botnet has been found that uses an unusual method for its bots to communicate to a Command and Control (C2) server. A machine infected with the "SYSCON" backdoor has been identified to use an FTP server for communication as well as a C2 server
Affected platforms
The following platforms are known to be affected:
Threat details
The SYSCON backdoor is distributed by attackers via malicious documents with macros. The FTP server tactics can potentially allow malicious activity to be overlooked, however, this method will also leave C2 traffic open to being monitored.
Remediation steps
Last edited: 17 February 2020 11:39 am