StealthFalcon Backdoor
StealthFalcon is a newly observed backdoor, created in 2015 by the Stealth Falcon advanced persistent threat group for use in their own campaigns.
Summary
StealthFalcon is a newly observed backdoor, created in 2015 by the Stealth Falcon advanced persistent threat group for use in their own campaigns.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how StealthFalcon is distributed.
Once installed, StealthFalcon will initiate a connection with a command and control (C2) server by using the standard Windows component Background Intelligent Transfer Service (BITS) before attempting to extract files. If StealthFalcon fails to connect to one of its two C2 severs, it will remove itself. Stealth Falcon is also able to install other payloads including cryptocurrency miners and ransomware tools.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:58 pm