LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company
#1
Information 
[Image: 180907-LuckyMouse-1.png]

What happened?
Since March 2018 we have discovered several infections where a previously unknown Trojan was injected into the lsass.exe system process memory. These implants were injected by the digitally signed 32- and 64-bit network filtering driver NDISProxy. Interestingly, this driver is signed with a digital certificate that belongs to Chinese company LeagSoft, a developer of information security software based in Shenzhen, Guangdong. We informed the company about the issue via CN-CERT.
The campaign described in this report was active immediately prior to Central Asian high-level meeting and we suppose that actor behind still follows regional political agenda.

Which malicious modules are used?
The malware consists of three different modules:
  • A custom C++ installer that decrypts and drops the driver file in the corresponding system directory, creates a Windows autorun service for driver persistence and adds the encrypted in-memory Trojan to the system registry.
  • A network filtering driver (NDISProxy) that decrypts and injects the Trojan into memory and filters port 3389 (Remote Desktop Protocol, RDP) traffic in order to insert the Trojan’s C2 communications into it.
  • A last-stage C++ Trojan acting as HTTPS server that works together with the driver. It waits passively for communications from its C2, with two possible communication channels via ports 3389 and 443.

[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Surfshark VPN : Award-winning VPN servi...
How to change your...jasonX — 03:36
XYplorer
What's new in Rele...Kool — 11:44
uBOLite 2026.419.1519 (already available...
uBOLite 2026.419.1...harlan4096 — 09:04
K. STANDARD / PLUS / PREMIUM / KSOS 21.2...
K. STANDARD / PLUS ...harlan4096 — 09:02
Mozilla's MZLA Technologies Launches Thu...
MZLA Technologies,...harlan4096 — 08:43

[-]
Birthdays
Today's Birthdays
avatar (45)wapedDow
Upcoming Birthdays
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo

[-]
Online Staff
There are no staff members currently online.

>