Ketrum Backdoor
Ketrum is a newly observed backdoor developed by the Ke3chang advanced persistent threat group for use in their own campaigns. Believed to be created from two of the older tools, Ketrican and Okrum, it has been used attacks against European government organisations.
Summary
Ketrum is a newly observed backdoor developed by the Ke3chang advanced persistent threat group for use in their own campaigns. Believed to be created from two of the older tools, Ketrican and Okrum, it has been used attacks against European government organisations.
Affected platforms
The following platforms are known to be affected:
Threat details
As with other Ke3chang tools, there is little evidence detailing how Ketrum is delivered, with unconfirmed reports suggesting it may be delivered in drive-by downloads attacks after a period of extensive target profiling.
At the time of publication, there are two known variants of Ketrum, with one having more functionality. Ketrum 1 is able to spoof User Account Control settings and take screenshots, as well as create copies of cmd.exe to avoid detection. Ketrum 2 is appears to have no additional functionality beyond acting as a basis backdoor. Both variants are able to upload, download, or execute files and commands
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. |
Indicators of compromise
Last edited: 29 June 2021 12:01 pm