logo

DLL Side-Loading Strikes Again: Yokai Backdoor Bypasses Security

ID: 4dbb7f4a-cd03-550d-9fbd-b03f187aa3c9

STIX ID: report--4dbb7f4a-cd03-550d-9fbd-b03f187aa3c9

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-12-17

Date Updated: 2026-04-22

Author: do son

...
...

Netskope researchers disclosed a targeted campaign delivering the Yokai backdoor to Thai officials via malicious RAR archives containing LNK shortcuts that extract decoy documents and a dropper from Alternate Data Streams. The dropper installs a legitimate iTop Data Recovery executable (IdrInit.exe) which side-loads a malicious DLL (ProductStatistics3.dll) providing persistence (scheduled tasks, process duplication), command execution, and exfiltration via XOR-encrypted C2 communications to hardcoded IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.