Brushaloader Downloader Trojan
First observed in June 2018, Brushaloader is a downloader trojan affiliated with the TA544 (also known as Narwhal Spider) advanced persistent threat.
Summary
First observed in June 2018, Brushaloader is a downloader trojan affiliated with the TA544 (also known as Narwhal Spider) advanced persistent threat.
Affected platforms
The following platforms are known to be affected:
Threat details
Brushaloader is delivered as a RAR or ZIP archive files, containing a combination of VBScript and PowerShell content, distributed via large scale spam campaigns. When decompressed, this content is automatically executed to install Brushaloader. Additional script content is used to evade detection by security products and to ensure Brushaloader's persistence on the affected system.
Once installed, Brushaloader will connect to a command and control (C2) server to download a PowerShell script called PowerEnum. This script is used to collect user and system information, which is then sent back to the C2 server to determine which payloads to deploy. Secondary payloads delivered by Brushaloader include DanaBot, Gootkit, Nymaim, and Ursnif.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 11 January 2022 9:49 am