Toitoin Trojan

Malware updated 6 months ago (2024-05-05T00:18:05.521Z)
Download STIX
Preview STIX
The Toitoin Trojan is a sophisticated piece of malware that has been found to be part of a persistent campaign targeting businesses in the LATAM region. This malicious software infiltrates systems, often undetected, through suspicious downloads, emails, or websites. Once inside, it can steal personal information, disrupt operations, and transmit encoded system information, browser details, and Topaz OFD Protection Module information to its Command & Control (C&C) server located at http[:]//afroblack[.]shop/CasaMoveis\ClienteD.php. The Trojan operates by leveraging decrypted strings and performing checks on the system's Windows version, installed browsers, and the presence of the Topaz OFD - Protection Module. It adapts its behavior based on these factors. The InjectorDLL component of the Trojan injects ElevateInjectorDLL into the "explorer.exe" process. If necessary, it carries out a User Account Control (UAC) bypass to elevate the process privileges. Subsequently, the Toitoin Trojan is decrypted and injected into the "svchost.exe" process, as depicted in Figure 25. If the Trojan cannot locate the INI configuration file containing the URL to the C&C server, it resorts to sending the system information through a curl command. The final payload of the Toitoin Trojan uses custom XOR decryption routines to decode the configuration file containing the C&C server's URL. This Trojan represents a significant threat to businesses due to its ability to adapt based on the system's characteristics and its persistence in maintaining communication with its C&C server.
Description last updated: 2024-05-04T23:21:00.438Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Trojan
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Toitoin Malware is associated with Toitoin Trojan. The Toitoin malware is a sophisticated, multi-stage cyberattack campaign targeting businesses in the Latin American (LATAM) region. The attack begins with a phishing email containing a malicious ZIP archive that stealthily downloads onto the victim's system. It then deploys several modules, includinUnspecified
3
Source Document References
Information about the Toitoin Trojan Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more