logo

New Yokai Side-loaded Backdoor Targets Thai Officials

ID: c8105db4-601a-5901-a531-219cc5443c45

STIX ID: report--c8105db4-601a-5901-a531-219cc5443c45

Feed Name: Netskope Threat Labs

Threat Score
70/100

Date Published: 2024-12-13

Date Updated: 2026-04-28

Author: Nikhil Hegde

...
...

Netskope Threat Labs describes an infection chain where RAR-contained LNK shortcuts use alternate data streams to drop a legitimate iTop Data Recovery executable that side-loads a previously undocumented backdoor named "Yokai." The report details persistence mechanisms (scheduled task, mutex, process spawning), the bespoke XOR-based C2 protocol and encryption, supported commands (remote shell, command execution), observed C2 IPs/URLs and file artefacts, and provides detection and mitigation guidance including IOC listings and recommended network/content inspection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.