Darkhole Backdoor
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The malware predominantly relies on user interaction in social engineering attacks in the infection chain and has little advancements since its initial deployment. If infected, businesses would face risks to the confidentiality of sensitive data and could be susceptible to subsequent further malware attacks using Darkhole’s backdoor capabilities.
The malware targets Windows 2000, Windows XP, Windows Server 2003 machines and is also known as VirTool:Win32/VBInject (Microsoft); BackDoor-AMQ.dr (McAfee); or Backdoor.Win32.DarkHole.gm, Backdoor.Win32.DarkHole.gm (Kaspersky).
Once present on the targeted device, the malware uses memory hollowing as a simplistic anti-detection method. It unpacks several executables under the following file structure: %WINDIR%\Debug\result.dark %WINDIR%\Debug\fipst.exe.
Darkhole then makes changes to registry keys and system directory. It then makes additions to the system directory to authorise its own activity through the Windows firewall. The malware scrapes device and network information and then opens a listening port using the sfvin.exe on port 1080. This allows for a communication channel to be established to the C2 infrastructure, whereby instructions or additional malware can be received and gleaned data sent. Darkhole attempts to read the host’s browser password manager local database and credentials used in popular FTP client applications. Once obtained, these are sent to a C2 node, likely as part of a HTTP GET request.
Remediation steps
Last edited: 17 February 2020 12:41 pm