DropBook is a new type of malware that allows attackers to gain unauthorized access to computers and networks. It is a backdoor that can be used to steal personal information, disrupt operations, or hold data for ransom. DropBook is part of the Molerats threat actor's arsenal of tools and was used in recent attacks.
DropBook is unique because it receives instructions only through fake accounts on Facebook and Simplenote, the note-taking app for iOS. It can check installed programs and file names for reconnaissance, execute shell commands received from Facebook or Simplenote, and fetch additional payloads from Dropbox and run them.
The researchers believe that DropBook is the work of the same developer that made JhoneRAT, a remote access tool written in Python that uses legitimate services (Google Drive, Twitter, ImgBB, and Google Forms) for command and control, to store malicious documents, or exfiltrate data.
Description last updated: 2023-06-23T15:26:07.802Z