MasterMana Botnet Dropper
First observed in December 2018, MasterMana Botnet is, despite its name, a dropper believed to be operated by the Gorgon Group advanced persistent threat.
Summary
First observed in December 2018, MasterMana Botnet is, despite its name, a dropper believed to be operated by the Gorgon Group advanced persistent threat.
Affected platforms
The following platforms are known to be affected:
Threat details
MasterMana is typically delivered via phishing emails containing malicious macro-enabled Microsoft Excel attachments. Once executed, these documents will attempt to terminate any Microsoft Office processes. Following this, the payload will attempt to add three scheduled tasks along with registry key values to maintain persistence.
If successful, MasterMana will reach out to attacker-controlled domains, hosted on widely used blogging services. These domains will then redirect to command and control servers and begin downloading DLL or PowerShell code. The code attempts to inject itself into processes, with the goal of evading anti-virus products.
Once successfully injected into processes, MasterMana will then download and install either the AZORult or RevengeRAT remote access trojans.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:58 pm