YiBackdoor: Linked to IcedID and Latrodectus
ID: 06a221d7-a14b-50a8-8c31-9dfe3e02400a
STIX ID: report--06a221d7-a14b-50a8-8c31-9dfe3e02400a
Feed Name: Zscaler Security Research Blog
This technical analysis describes YiBackdoor, a Windows backdoor that employs anti-analysis checks, remote process injection via RtlExitUserProcess hooking, registry Run-key persistence (using randomized names), encrypted embedded configuration, dynamic TripleDES-based network encryption keyed by day-of-week offsets, an HTTP(S) JSON command-and-control channel exposing multiple remote commands (system info, screenshot, shell/PowerShell execution, plugin management), and an extensible encrypted plugin system; the report also documents notable code overlaps with IcedID and Latrodectus suggesting shared code or lineage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
