ThreatLabz
ID: 04703314-5bdb-5a84-b548-2b1efb82207e
STIX ID: report--04703314-5bdb-5a84-b548-2b1efb82207e
Feed Name: Zscaler Security Research Blog
This report provides a technical analysis of the MoonWalk backdoor (deployed via the DodgeBox loader) outlining its modular architecture, evasion techniques (DLL hollowing, DLL unhooking, call stack spoofing, Windows Fibers), and a covert Google Drive-based C2 using a custom encrypted protocol and ECDH/AES handshake. The analysis documents configuration storage, embedded plugins (C2 and utility), filepaths and OAuth-related credentials in configuration, the custom encoding/encryption scheme for exchanged files, and built-in handlers such as token impersonation and remote command execution, noting similarities to tools attributed to APT41.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
