logo

Msupedge Backdoor Targeting Taiwanese University (Campaign)

ID: f0fcc05b-72e5-57b1-9efc-325ba65adcbb

STIX ID: report--f0fcc05b-72e5-57b1-9efc-325ba65adcbb

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-08-19

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Backdoor.Msupedge is a DNS-tunneling backdoor used in an attack against a Taiwanese university, likely leveraging PHP CVE-2024-4577 for remote code execution on Windows. The backdoor installs as DLLs (e.g., wuplog.dll, wmiclnt.dll) and uses a dnscat2-based DNS channel to receive commands encoded in DNS queries and TXT records; it alters behavior based on the third octet of resolved IP addresses and supports actions such as creating processes, downloading files, and returning execution results.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.