CASHY200 Backdoor
First observed in early 2018, CASHY200 is a PowerShell-based backdoor associated with the larger xHunt malware campaign.
Summary
First observed in early 2018, CASHY200 is a PowerShell-based backdoor associated with the larger xHunt malware campaign.
Affected platforms
The following platforms are known to be affected:
Threat details
Despite initially being heavily targeted at government and shipping organisations in the Middle East, it now appears to be affecting organisations throughout Europe. CASHY200 is delivered via malicious Microsoft Office attachments distributed through email phishing campaigns. When opened, a preliminary script in the attachments will execute CASHY200 directly in memory.
If successfully executed, CASHY200 will connect to a command and control server, using a bespoke DNS tunnelling protocol in order to bypass standard network monitoring, before awaiting further commands. CASHY200 variants are able to extract files as well as install secondary payloads.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:58 pm