Okrum Backdoor
Okrum is a simple backdoor created by the Ke3chang (also known as APT15) advanced persistent threat. First observed in 2016 in campaigns against Eastern European government organisations, Ke3chang now uses Okrum against targets globally.
Summary
Okrum is a simple backdoor created by the Ke3chang (also known as APT15) advanced persistent threat. First observed in 2016 in campaigns against Eastern European government organisations, Ke3chang now uses Okrum against targets globally.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, Okrum is delivered as an encrypted Dynamic-link Library file embedded within a PNG image file, with Ke3chang making extensive use of steganographic techniques to avoid detection. This file is decrypted and executed by an unnamed preliminary installer, likely a variant of the MirageFox remote access trojan.
Once installed, Okrum escalates its privileges by calling the ImpersonateLoggedOnUser API before collecting user, system, and network information and sending it to a command and control server over HTTP. As stated previously, Okrum is not technically complex and can only execute shell commands by default. However, Ke3chang are able to leverage this capability to install their own tools including the Ketrican, RoyalCLI, and RoyalDNS, as well as to execute third-party applications present on the affected system.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:51 pm