VBShower Backdoor
VBShower is a newly observed PowerShell-based polymorphic backdoor, created by the Inception advanced persistent threat group to replace their older PowerShower malware.
Summary
VBShower is a newly observed PowerShell-based polymorphic backdoor, created by the Inception advanced persistent threat group to replace their older PowerShower malware.
Affected platforms
The following platforms are known to be affected:
Threat details
As with PowerShower, Inception delivers VBShower using an embedded HTA file distributed via targeted spam or spear-phishing campaigns. When opened, this file will execute an unnamed launcher, which in turn executes VBShower. The HTA file also contains a context file which is used by VBShower to connect to a command control (C2) server.
Once installed, VBShower will download VBS files containing the intended payloads from the C2 server, which are then installed on the affected system. In some campaigns, VBShower will also install PowerShower, which is then used to extract user credentials and files.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 11 January 2022 9:20 am