Skip to main content

BOOSTWRITE Backdoor

BOOSTWRITE is a newly observed in-memory dropper created by the FIN7 advanced persistent threat group for use in their own campaigns.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

BOOSTWRITE is a newly observed in-memory dropper created by the FIN7 advanced persistent threat group for use in their own campaigns.


Affected platforms

The following platforms are known to be affected:

Threat details

At the time of publication, it is unclear how BOOSTWRITE is delivered, although FIN7 are known to use advanced spear-phishing campaigns to deliver their tools. However, it is known that BOOSTWRITE will attempt to alter the search order for the Dwrite.dll Dynamic-link Library file to ensure it is launched at startup in place of the legitimate file.

Once loaded, BOOSTWRITE will scan its own image to retrieve a multi-XOR key in order to decode further data stored within the image. This data contains an IP address and port for a command and control server, which BOOSTWRITE will connect to in order to obtain a decryption key for two embedded ChaCha-encrypted payloads. These payloads will then be loaded straight into the affected system's memory, bypassing running anti-virus and security services.


Remediation steps

Type Step

To prevent and detect an infection, ensure that:

  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, anti-virus and other security products are kept up-to-date.
  • Regular anti-virus and security scans are performed on your organisation’s estate.
  • All day-to-day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from affected devices should be reset on a clean computer.
  • Your organisation adopts a holistic all-round approach to Cyber Security as advocated by the 10 Steps to Cyber Security.

Last edited: 14 February 2020 2:57 pm