DePriMon Downloader Trojan
First observed in March 2017, DePriMon (Default Print Monitor) is an advanced fileless downloader believed to be associated with the Lamberts (also known as ColoredLamberts or Longhorn) advanced persistent threat group.
Summary
First observed in March 2017, DePriMon (Default Print Monitor) is an advanced fileless downloader believed to be associated with the Lamberts (also known as ColoredLamberts or Longhorn) advanced persistent threat group.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how DePriMon is distributed. However, all reported instances of DePriMon infection have included a number of Lamberts tools, suggesting it may be delivered by one of these tools, possibly the White or Gray Lambert backdoors.
Once delivered, DePriMon's first stage will attempt to hijack the search-order of the Windows print spooler service, spoolsv.exe, so that the second stage may use its default privileges. If successful, the second stage will then connect to a command and control (C2) server over TLS using Windows Secure Channel, before downloading any intended payloads from the C2 server and dropping them directly into memory.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:57 pm