Icefog Backdoor
First observed in 2011, Icefog (also known as Fucobha) is an advanced backdoor created by the advanced persistent threat (APT) group of the same name.
Summary
First observed in 2011, Icefog (also known as Fucobha) is an advanced backdoor created by the advanced persistent threat (APT) group of the same name.
Affected platforms
The following platforms are known to be affected:
Threat details
Despite Icefog APT activities appearing to cease in 2013, the Icefog backdoor has continued to see intermittent use by other groups in the years since.
Icefog is delivered via spear-phishing emails containing malicious attachments. When opened, these attachments execute one or more Microsoft Office, Hangul Word Processor, Oracle Java or HLP file exploits in order to gain access to the affected device before extracting and installing Icefog.
At the time of publication, there are two observed Icefog variants, Icefog-P and Icefog-M, with each having slight variations in capability. Icefog-P is a comprehensive backdoor and remote access trojan able to execute commands, install payloads, exfiltrate data and terminate processes over an HTTP command and control (C2) connection. Icefog-M is based on Icefog-P but switches to an HTTPS connection for C2 communications and can install file-less payloads using a new loader.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
CVE Vulnerabilities
Last edited: 17 January 2022 7:16 pm