ElectricFish Backdoor
ElectricFish is a newly observed backdoor created by the HIDDEN COBRA advanced persistent threat group for use in their own campaigns.
Summary
ElectricFish is a newly observed backdoor created by the HIDDEN COBRA advanced persistent threat group for use in their own campaigns.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how ElectricFish is distributed, although it is likely to be delivered post-exploitation as part of HIDDEN COBRA's exfiltration processes.
Once installed, ElectricFish will initiate a connection with a command and control (C2) server using a bespoke protocol. It will then open the necessary ports to allow communication between the C2 server and other HIDDEN COBRA malware, such as TYPEFRAME and HOPLIGHT, on the affected device.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:43 pm