SMBdoor backdoor PoC: inspired by the NSA

SMBdoor: A security researcher created a new backdoor inspired by NSA's malicious software leaked in the spring of 2017.

The new malware is called SMBdoor and is the work of Sean Dillon, a security researcher at RiskSence (@zerosum0x0).

SMBdoor

Dillon designed SMBdoor as a Windows kernel driver, which, once installed on a computer, logs APIs not registered in the srvnet.sys process to register as a valid process for SMB (Server Message Block) connections.

Malicious software is unbelievable as it does not connect to local slots, open ports, and does not fit into existing features, thus avoiding the activation of virus protection alerts.

Its design was inspired by a similar behavior observed by Dillon in the DoublePulsar and DarkPulsar, εμφυτεύματα κακόβουλου λογισμικού σχεδιασμένα από την NSA που διέρρευσαν στο διαδίκτυο από την group The Shadow Brokers.

However, some users may be wondering (and rightly so): Why did a security researcher create malware?

Dillon reported to ZDNet that the SMBdoor's vulnerability is not weaponized and that cybercriminals cannot download it from GitHub to infect users in the same way they can download and deploy versions of the NSA's DoublePulsar.

Let us also mention that each PoC that is circulated by researchers is recorded and analyzed by security companies and security software providers as well as by PoC software developers /

"SMBdoor comes with practical limitations that make it mostly academic research, but I thought it would be interesting to share it."

There are restrictions on PoC that an intruder must overcome, ”he added. "The most important limitation is that modern Windows tries to block the core code without a valid digital signature.

___________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).