skip-2.0 Backdoor
skip-2.0 is a newly observed backdoor created by the Winnti advanced persistent threat group.
Summary
skip-2.0 is a newly observed backdoor created by the Winnti advanced persistent threat group.
Affected platforms
The following platforms are known to be affected:
Threat details
Based on earlier versions of their PortReuse and ShadowPad tools, it is believed to be the first publicly known backdoor to target Microsoft SQL (MSSQL) servers. As with PortReuse, skip-2.0 is delivered embedded within a custom VMProtected launcher, which itself appears to be distributed via compromised hosting servers, supply-chain attacks, or spear-phishing campaigns. When executed, this launcher will attempt to hijack the search order for the TSVIPSrv.dll file to maintain persistence before unpacking and launching a secondary loader, which will then decrypt and execute skip-2.0.
Once installed, skip-2.0 will attempt to inject itself into the sqlserv.exe process so that it may retrieve sqllang.dll. It will then locate and hook several functions related to authentication and event logging within this DLL. If successful, skip-2.0 will begin listening for login requests to the affected system, bypassing authentication measures for any request using a hard-coded 'magic' password.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:54 pm