FlawedGrace Remote Access Trojan
First observed in August 2017, FlawedGrace is a modular remote access trojan. Written in C--, it uses several advanced obfuscation techniques to disguise itself on affected devices.
Summary
First observed in August 2017, FlawedGrace is a modular remote access trojan. Written in C--, it uses several advanced obfuscation techniques to disguise itself on affected devices.
Affected platforms
The following platforms are known to be affected:
Threat details
FlawedGrace is primarily distributed via spam or phishing campaigns; but it has also been observed being delivered by several backdoors, including the recently observed ServHelper.
Once installed, FlawedGrace will connect to a command and control server before awaiting further commands. By default, it can download and execute secondary payloads, collect user and system credentials, terminate security and monitoring services or encrypt files. Additional modules can be installed prior to, or after, installation.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:50 pm