Drbcontrol

Malware updated 4 months ago (2024-11-29T13:57:26.708Z)
Download STIX
Preview STIX
DRBControl is a malicious software (malware) that infiltrates computer systems, often undetected, to exploit and damage them. This malware can steal personal information, disrupt operations, or even hold data hostage for ransom. It was discovered that the same library used in the DRBControl backdoor was also found in several samples of the PlugX backdoor, a tool popular among Chinese-speaking groups. Interestingly, this specific library has not been detected in any other known malware. Upon comparison of samples of the PlugY implant and the DRBControl backdoor, it was revealed that these two samples share the exact same architecture. The command code for taking screenshots, retrieving information about connected disks, and active windows in the DRBControl backdoor are identical to those in the implant. However, the analysis of the implant is still ongoing, but initial findings indicate that the code of the DRBControl backdoor was used in its development. The DRBControl backdoor supports three different protocols for communicating with C2, showing a significant resemblance to the code of the implant. Several companies attribute the DRBControl backdoor, also known as Clambling, to the APT27 group. This finding suggests a high likelihood that the APT27 group may have played a role in the development and deployment of this malware.
Description last updated: 2024-10-17T11:56:00.230Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Drbcontrol Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securelist
4 months ago
Securelist
7 months ago