Xxmm

Malware updated 4 months ago (2024-05-05T01:18:22.607Z)
Download STIX
Preview STIX
xxmm is a malicious software (malware) that has been observed to be used in tandem with other malware types, including Daserf and Datper, by the threat group BRONZE BUTLER. These malware communicate with their command and control (C2) servers via HTTP, encrypting commands and data using specific algorithms. The xxmm malware is also known as KVNDM and operates as a downloader, featuring code similar to its main payload. It downloads additional payloads such as Daserf, Datper, or another instance of xxmm in a compressed and encoded format, typically executing the downloaded malware after decoding the file. The xxmm malware exhibits sophisticated features designed to exploit and damage targeted systems. For instance, it incorporates a User Account Control (UAC) bypass tool for privilege escalation prior to stealing passwords. Furthermore, it includes an uploading feature that enables data exfiltration. Once this process is complete, the uploader (or Datper or xxmm) immediately uses the "del" command to delete the RAR archives, thereby covering its tracks. CTU researchers have identified an xxmm builder for the malware, suggesting that threat actors are customizing the xxmm settings based on their specific targets. Several xxmm samples analyzed were found to incorporate Mimikatz, a powerful utility used for extracting plaintexts passwords, hashes, PIN codes and Kerberos tickets from memory. This allows the threat actors to issue Mimikatz commands directly from within xxmm, increasing the potency of their attacks. As of this publication, the continued use of xxmm in cyber operations underlines its efficacy as a tool for cyber exploitation and data theft.
Description last updated: 2024-05-05T00:42:17.015Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Kvndm
2
None
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Trojan
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
IDTypeVotesProfile Description
Daserfis related to
2
Daserf is a sophisticated malware, custom-developed for use in Tick's cyberespionage campaigns. It is capable of exploiting and damaging computer systems by stealing personal information, disrupting operations, and relaying stolen data back to attacker-controlled servers. The Daserf Trojan employs n
Source Document References
Information about the Xxmm Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
BRONZE BUTLER Hacker Group Targets Japanese Enterprises
MITRE
2 years ago
REDBALDKNIGHT’s Daserf Backdoor Now Uses Steganography