DLL Side-Loading Strikes Again: Yokai Backdoor Bypasses Security
ID: 4dbb7f4a-cd03-550d-9fbd-b03f187aa3c9
STIX ID: report--4dbb7f4a-cd03-550d-9fbd-b03f187aa3c9
Feed Name: securityonline.info
Netskope researchers disclosed a targeted campaign delivering the Yokai backdoor to Thai officials via malicious RAR archives containing LNK shortcuts that extract decoy documents and a dropper from Alternate Data Streams. The dropper installs a legitimate iTop Data Recovery executable (IdrInit.exe) which side-loads a malicious DLL (ProductStatistics3.dll) providing persistence (scheduled tasks, process duplication), command execution, and exfiltration via XOR-encrypted C2 communications to hardcoded IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
