Parallax Remote Access Trojan
First observed in December 2019, Parallax is an MASM-based remote access trojan sold through a number of hacking forums, with its creators offering a number of additional support services as well as bespoke development based on affiliate feedback.
Summary
First observed in December 2019, Parallax is an MASM-based remote access trojan sold through a number of hacking forums, with its creators offering a number of additional support services as well as bespoke development based on affiliate feedback.
Affected platforms
The following platforms are known to be affected:
Threat details
As with most malware-as-a-service (MaaS) tools, Parallax can be delivered in any vector affiliates wish. However, at the time of publication, it has only been observed being distributed via spam campaigns.
Once installed, Parallax will create a scheduled tasks as well as a shortcut to itself in the Startup folder to ensure persistence. It will then connect to a command and control server hosted on the Duck DNS service and await further commands. By default, Parallax has the following capabilities, although its creators appear to be adding new features monthly:
- Remote Desktop session creation
- File transfer, execution, and deletion
- Secondary payload installation
- Email and financial credential extraction
For further information:
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Indicators of compromise
CVE Vulnerabilities
Last edited: 29 June 2021 12:00 pm