New Yokai Side-loaded Backdoor Targets Thai Officials
ID: c8105db4-601a-5901-a531-219cc5443c45
STIX ID: report--c8105db4-601a-5901-a531-219cc5443c45
Feed Name: Netskope Threat Labs
Netskope Threat Labs describes an infection chain where RAR-contained LNK shortcuts use alternate data streams to drop a legitimate iTop Data Recovery executable that side-loads a previously undocumented backdoor named "Yokai." The report details persistence mechanisms (scheduled task, mutex, process spawning), the bespoke XOR-based C2 protocol and encryption, supported commands (remote shell, command execution), observed C2 IPs/URLs and file artefacts, and provides detection and mitigation guidance including IOC listings and recommended network/content inspection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
