PNG Dropper Downloader
First observed in August 2017, PNG Dropper (sometimes stylised as png_dropper) is a downloader trojan developed and used by the Turla advanced persistent threat group.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
First observed in August 2017, PNG Dropper (sometimes stylised as png_dropper) is a downloader trojan developed and used by the Turla advanced persistent threat group.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication it is unclear how PNG Dropper is distributed, although Turla are known to use highly targeted spear-phishing campaigns to deliver their other tools. It is delivered disguised within the publicly available JPEGView image viewer or 7-Zip file archive utility. These tools are packaged with a series of extra PNG files containing PNG Dropper and the intended payload. When opened, these tools will compile and execute PNG Dropper.
Once installed, PNG Dropper will extract, recompile and install the payload from the remaining PNG files. Newer variants can extract encrypted portable executable files from the registry.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 17 February 2020 1:00 pm