Crugup Backdoor
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Initially delivered through malicious URLs in watering hole attacks, Crugup drops copies of svchost.exe. It then executes commands to change the permissions of these copies to prevent their removal. The filepaths of these copies use a randomly generated prefix to avoid signature-based detection.
Registry entries are added to automatically run Crugup during system start-up and alter the netsh.exe utility to bypass Windows Firewall. This allows Internet Explorer to be used to communicate with the malware's C2 infrastructure. Crugup can then connect to remote sites, download and execute files and perform denial of service attacks. If it detects certain files open in running processes it will cause a restart of the affected device.
Crugup collect information on the volume serial number, operating system version and administrative privileges status before communicating this via HTTP POST. HTTP GET requests have used URL's named after legitimate site in order to avoid detection.
Remediation advice
To prevent and detect a backdoor infection, ensure that:Remediation steps
Last edited: 17 February 2020 12:41 pm