Qrypter MaaS Remote Access Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Qrypter is typically delivered via malicious email campaigns, each consisting of several hundred messages. When installed, it will download and execute two randomly-named .vbs files in the %Temp% folder to gather information on the firewall and antivirus products present on the device. Registry entries are created to terminate and disable a number of security-related processes, lower overall security settings and initiate Qrypter at startup. Finally, a connection to a Tor-based command and control server is initiated.
As a plugin-based tool, Qrypter has a wide range of functionality, including:
- Remote desktop connection
- Webcam access
- File system manipulation
- Installation of additional files
- Task manager control
QUA R&D claim Qrypter is undetectable by all major antivirus products. They also offer a large number of cracked malware products in order to entice buyers to their site.
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
Last edited: 17 February 2020 12:53 pm