Whenever these files are launched during system startup, a backdoor embedded in the C Runtime initialization code activates. This backdoor operates in a dedicated thread and initiates HTTP GET requests to a malicious command-and-control server designed to typosquat the legitimate domain. Registered just over a week before the campaign commenced, this server responds with shell commands that utilize PowerShell to download and execute the first-stage payload. This initial payload acts as an advanced information collector, compiling extensive system profiling data such as MAC addresses, hostnames, running processes, installed software, and system locales. Embedded within this .NET executable are strings written in Chinese, providing early clues regarding the potential origin of the operators. Telemetry data indicates that the threat actors sifted through the massive volume of profiling data to select high-value targets for subsequent exploitation. Out of thousands of initial infections, only about a dozen machines belonging to government, scientific, manufacturing, and retail sectors in Russia, Belarus, and Thailand received a secondary payload. This second stage is a minimalistic backdoor deployed via a shellcode loader that utilizes RC4 encryption to execute the malicious payload directly in memory.
Inquisition Daemonhunt - modification for Dawn of War: Dark Crusade (788 hits) BF2CC + BF2CCDaemon - Allows easy setup and management of the BF2 dedicated server application for both Windows and Linux (749 hits)