Skip to main content

Crugup Backdoor

First observed in 2014, Crugup is a backdoor and information stealer. It has anti-remediation capabilities and specifically uses Internet Explorer for command and control (C2) communications.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

First observed in 2014, Crugup is a backdoor and information stealer. It has anti-remediation capabilities and specifically uses Internet Explorer for command and control (C2) communications.

Affected platforms

The following platforms are known to be affected:

Threat details

Initially delivered through malicious URLs in watering hole attacks, Crugup drops copies of svchost.exe. It then executes commands to change the permissions of these copies to prevent their removal. The filepaths of these copies use a randomly generated prefix to avoid signature-based detection.

Registry entries are added to automatically run Crugup during system start-up and alter the netsh.exe utility to bypass Windows Firewall. This allows Internet Explorer to be used to communicate with the malware's C2 infrastructure. Crugup can then connect to remote sites, download and execute files and perform denial of service attacks. If it detects certain files open in running processes it will cause a restart of the affected device.

Crugup collect information on the volume serial number, operating system version and administrative privileges status before communicating this via HTTP POST. HTTP GET requests have used URL's named after legitimate site in order to avoid detection.


Remediation advice

To prevent and detect a backdoor infection, ensure that:

Remediation steps

Type Step
  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, antivirus and other security products are kept up to date.
  • All day to day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place and password reuse is discouraged.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from infected machines should be reset on a clean computer.

Additionally, users should be wary of changes in the way commonly used sites behave.


Last edited: 17 February 2020 12:41 pm