Skip to main content

SYSCON Backdoor Uses FTP as a C2 Channel

A botnet has been found that uses an unusual method for its bots to communicate to a Command and Control (C2) server. A machine infected with the "SYSCON" backdoor has been identified to use an FTP server for communication as well as a C2 server
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A botnet has been found that uses an unusual method for its bots to communicate to a Command and Control (C2) server. A machine infected with the "SYSCON" backdoor has been identified to use an FTP server for communication as well as a C2 server

Affected platforms

The following platforms are known to be affected:

Threat details

The SYSCON backdoor is distributed by attackers via malicious documents with macros. The FTP server tactics can potentially allow malicious activity to be overlooked, however, this method will also leave C2 traffic open to being monitored.

Remediation steps

Type Step
  • All employees should be educated on the risks of phishing, specifically, how to identify such attempts and whom to contact if a phishing attack is identified.
  • To prevent the backdoor being used, FTP traffic should be blocked if it is not necessary for business purposes. 

Last edited: 17 February 2020 11:39 am