Advanced stealth has been exhibited by the newly emergent MystRodX backdoor, also known as ChronosRAT, reports The Hacker News.MystRodX has been spread using a dropper that monitors debuggers and virtual machines before proceeding with next-stage payload decryption, with the payload promptly launched after the daytime process is verified to be non-operational, according to an analysis from QiAnXin XLab researchers.Additional findings also revealed MystRodX's ability to serve as a passive backdoor that is run following DNS or ICMP network packet delivery."Unlike well-known stealth backdoors like SYNful Knock, which manipulates TCP header fields to hide commands, MystRodX uses a simpler yet effective approach: it hides activation instructions directly in the payload of ICMP packets or within DNS query domains," said researchers.Such findings follow a Palo Alto Networks study noting MystRodX to have been leveraged in attacks by the CL-STA-0969 threat cluster associated with China-linked Liminal Panda cyberespionage hackers.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
AdwareYou can skip this ad in 5 seconds
