LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company
#1
Information 
[Image: 180907-LuckyMouse-1.png]

What happened?
Since March 2018 we have discovered several infections where a previously unknown Trojan was injected into the lsass.exe system process memory. These implants were injected by the digitally signed 32- and 64-bit network filtering driver NDISProxy. Interestingly, this driver is signed with a digital certificate that belongs to Chinese company LeagSoft, a developer of information security software based in Shenzhen, Guangdong. We informed the company about the issue via CN-CERT.
The campaign described in this report was active immediately prior to Central Asian high-level meeting and we suppose that actor behind still follows regional political agenda.

Which malicious modules are used?
The malware consists of three different modules:
  • A custom C++ installer that decrypts and drops the driver file in the corresponding system directory, creates a Windows autorun service for driver persistence and adds the encrypted in-memory Trojan to the system registry.
  • A network filtering driver (NDISProxy) that decrypts and injects the Trojan into memory and filters port 3389 (Remote Desktop Protocol, RDP) traffic in order to insert the Trojan’s C2 communications into it.
  • A last-stage C++ Trojan acting as HTTPS server that works together with the driver. It waits passively for communications from its C2, with two possible communication channels via ports 3389 and 443.

[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
GFYI [Official] HitmanPro.Alert Mother'...
Hi guys, So sorry...jasonX — 20:56
GFYI [Official] Master PDF Editor Mothe...
Hi guys, So sorry...jasonX — 20:54
AV-Comparatives: EDR-Detection-Validatio...
EDR-Detection-Vali...harlan4096 — 11:17
Rufus 4.8
Rufus 4.8 (stable)...harlan4096 — 11:15
Antivirus Removal Tool 2025.06 (v.1)
Hello everyone, ...harlan4096 — 11:13

[-]
Birthdays
Today's Birthdays
avatar (39)Julioagopy
avatar (49)aolaupitt2558
Upcoming Birthdays
avatar (38)Tedscolo
avatar (45)brakasig
avatar (44)JamesReshy
avatar (46)Francisemefe
avatar (39)leoniDup
avatar (38)Patrizaancem
avatar (38)biobdam
avatar (39)storoBox
avatar (47)kinotHeemn
avatar (38)Ceballos1976
avatar (39)efynu
avatar (31)horancos

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>