logo

ThreatLabz

ID: 04703314-5bdb-5a84-b548-2b1efb82207e

STIX ID: report--04703314-5bdb-5a84-b548-2b1efb82207e

Feed Name: Zscaler Security Research Blog

Threat Score
88/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report provides a technical analysis of the MoonWalk backdoor (deployed via the DodgeBox loader) outlining its modular architecture, evasion techniques (DLL hollowing, DLL unhooking, call stack spoofing, Windows Fibers), and a covert Google Drive-based C2 using a custom encrypted protocol and ECDH/AES handshake. The analysis documents configuration storage, embedded plugins (C2 and utility), filepaths and OAuth-related credentials in configuration, the custom encoding/encryption scheme for exchanged files, and built-in handlers such as token impersonation and remote command execution, noting similarities to tools attributed to APT41.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.