MiniDuke Remote Access Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Sophisticated PDF lure documents distributed in phishing campaigns are used to deliver MiniDuke. These documents contain exploits for two Adobe Reader vulnerabilities as well as a downloader for the main MiniDuke DLL module.
Once installed, MiniDuke will create a new task in the Windows Task Scheduler to spawn an instance of itself at start-up before connecting to a command and control server. It's primary function appears to be data exfiltration, collecting and transmitting files based on their extension and filename, however it is also able to install secondary malware and execute commands.
For further information
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
CVE Vulnerabilities
Last edited: 17 February 2020 12:49 pm