Zepakab Downloader Trojan
Zepakab is a newly observed downloader trojan that makes extensive use of open-source AutoIT libraries and is believed to have been created by the APT28 advanced persistent threat.
Summary
Zepakab is a newly observed downloader trojan that makes extensive use of open-source AutoIT libraries and is believed to have been created by the APT28 advanced persistent threat.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication it is unclear how Zepakab is delivered, although APT28 are known for using highly targeted spear phishing campaigns to distribute their malware.
Once installed, Zepakab will collect system and user information before connecting to a command and control (C2) server over HTTPS. The C2 server will then use this information to determine if the affected system is a valid target, before sending a payload back to Zepakab for installation. It is currently unclear what payloads have been delivered using Zepakab, although it is likely APT28 are using Zepakab alongside their other tools.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 11 January 2022 9:40 am