BOOSTWRITE Backdoor
BOOSTWRITE is a newly observed in-memory dropper created by the FIN7 advanced persistent threat group for use in their own campaigns.
Summary
BOOSTWRITE is a newly observed in-memory dropper created by the FIN7 advanced persistent threat group for use in their own campaigns.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how BOOSTWRITE is delivered, although FIN7 are known to use advanced spear-phishing campaigns to deliver their tools. However, it is known that BOOSTWRITE will attempt to alter the search order for the Dwrite.dll Dynamic-link Library file to ensure it is launched at startup in place of the legitimate file.
Once loaded, BOOSTWRITE will scan its own image to retrieve a multi-XOR key in order to decode further data stored within the image. This data contains an IP address and port for a command and control server, which BOOSTWRITE will connect to in order to obtain a decryption key for two embedded ChaCha-encrypted payloads. These payloads will then be loaded straight into the affected system's memory, bypassing running anti-virus and security services.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:57 pm