Summary
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how Murkios is delivered, although there are unconfirmed reports indicating it may be distributed as an attachment in small-scale spam campaigns.
Once executed, Murkios will drop five EXE files, each with different functionality:
- start.exe - Checks operating system version, adds malicious user accounts, bypasses User Account Control restrictions and installs other modules.
- systems.exe - Installs RDP Wrapper Library, a legitimate Remote Desktop Protocol tool designed for multiple concurrent sessions.
- uid.txt - Creates and stores a unique identifier for the affected system.
- winsys.exe - Captures screen images and sends all extracted information back to the C2 server using an SSH tunnel. Will also receive the UID from the C2 server.
- winsystem.exe - A variant of the legitimate PuTTY Link (Plink) network session tool, used to connect to other devices on the same network.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:51 pm