QSC: Multi-Plugin Malware Framework Installs Backdoor on Windows
ID: c743e878-aef0-5e29-aee1-0f59830ac590
STIX ID: report--c743e878-aef0-5e29-aee1-0f59830ac590
Feed Name: GBHackers
**Executive summary:** The report describes deployment of the QSC framework (loader.dll, Core, Network, File Manager, qscShell.dll) and a Golang backdoor (GoClient) by the CloudComputating actor against an ISP in West Asia; attackers used Quarian to deploy QSC and GoClient, performed lateral movement using stolen domain admin credentials and WMIC, created services and reflective-injected modules for C2 and file operations, used tools like we.exe and pf.exe to perform pass-the-hash attacks and traffic forwarding, and ultimately created a shadow copy to exfiltrate the NTDS database and other sensitive data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
