Disclosing the BLOODALCHEMY backdoor
ID: 14478b56-6b99-51f2-8957-0e82a6a40630
STIX ID: report--14478b56-6b99-51f2-8957-0e82a6a40630
Feed Name: Elastic Security Labs
BLOODALCHEMY is an x86 backdoor discovered as injected shellcode in a signed benign process and likely loaded via a malicious BrLogAPI.dll sideload; the report analyzes its custom string obfuscation, configuration decoding, multiple persistence methods (service, registry, scheduled task, COM), execution modes (in-thread, new process injection, service), C2 channels (HTTP, named pipes, sockets, and others), limited command set, YARA detections, and provides IOCs and hashes while noting it appears modular and under active development as part of the REF5961 intrusion set.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
