CrashReporter Backdoor
First observed in June 2019, CrashReporter is a backdoor believed to have been created by the Lazarus Group advanced persistent threat or based heavily on their other tools.
Summary
First observed in June 2019, CrashReporter is a backdoor believed to have been created by the Lazarus Group advanced persistent threat or based heavily on their other tools.
Affected platforms
The following platforms are known to be affected:
Threat details
CrashReporter is delivered through the JMT Trader cryptocurrency trading client, which is itself available to download through a number of GitHub repositories. This application appears to be identical to the legitimate QT Bitcoin Trader platform, suggesting CrashReporter's operators have cloned it's repository for their own uses. During installation, JMT Trader's installer will extract CrashReporter and save it to the %AppData% folder, before creating the schedule task JMTCrashReporter to execute it whenever a user logs into the affected system.
Once installed, CrashReporter will connect to a command and control server to download any intended payloads, which are then installed on the affected system.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:55 pm