A new cross-platform backdoor called SysJoker was found targeting machines running Windows, Linux, and macOS operating systems as part of an ongoing espionage campaign which is believed to have been started during the second half of 2021.
Researchers Avigayil Mechtinger, Ryan Robinson, and Nicole Fishbein from Israeli cybersecurity company Intezer, noted that SysJoker masquerades as a system update and generates its [command-and-control server] by decoding a string retrieved from a text file hosted on Google Drive. Based on victimology and malware’s behavior, they assess that SysJoker is after specific targets.
The company attributes the work to an advanced threat actor and has discovered evidence of the implant in December 2021 during an active attack against a Linux-based web server belonging to an unnamed educational institution.
A C++-based malware, SysJoker is delivered via a dropper file from a remote server which upon execution, is engineered to collect information about the compromised host, such as MAC address, user name, physical media serial number, and IP address, all of which are encoded and transmitted back to the server.
The connections to the attacker-controlled server are established by extracting the domain’s URL from a hard-coded Google Drive link that hosts a text file (“domain.txt”), enabling the server to relay instructions to the machine that allow the malware to run arbitrary commands and executables, following which the results are beamed back.
Credit : Intezer

















Comments