Malware

Novel covert MystRodX backdoor examined

Advanced stealth has been exhibited by the newly emergent MystRodX backdoor, also known as ChronosRAT, reports The Hacker News.

MystRodX has been spread using a dropper that monitors debuggers and virtual machines before proceeding with next-stage payload decryption, with the payload promptly launched after the daytime process is verified to be non-operational, according to an analysis from QiAnXin XLab researchers.

Additional findings also revealed MystRodX's ability to serve as a passive backdoor that is run following DNS or ICMP network packet delivery.

"Unlike well-known stealth backdoors like SYNful Knock, which manipulates TCP header fields to hide commands, MystRodX uses a simpler yet effective approach: it hides activation instructions directly in the payload of ICMP packets or within DNS query domains," said researchers.

Such findings follow a Palo Alto Networks study noting MystRodX to have been leveraged in attacks by the CL-STA-0969 threat cluster associated with China-linked Liminal Panda cyberespionage hackers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds