Threats Feed
- Public
The Espionage Arsenal of Nazar's Backdoor
The Nazar APT's backdoor, showcases a suite of espionage tools used for malicious activities. It employs a passive approach, utilizing the discontinued Packet Sniffer SDK (PSSDK) for communication. Key capabilities include a keylogger that saves data in %WINSYSDIR%\report.txt, system shutdown through an OLE object, screen capture saved in %CWD%\z.png, audio recording saved as %WINSYSDIR%\music.mp3, and enumeration of drives, files, and installed programs with results stored in %WINSYSDIR%. Additionally, it can remove files, list devices, perform a ping operation, and gather OS information. This malware is specifically designed for espionage, indicating a focus on data extraction and system information discovery.
read more about The Espionage Arsenal of Nazar's Backdoor - Public
Nazar APT's Complex Cyber Toolkit: From Keylogging to Passive Backdoors
The Nazar APT, active since at least 2010, employs a modular toolkit for cyber espionage. Its main dropper registers multiple DLLs as OLE controls in the Windows registry using 'regsvr32.exe'. It includes a service disguised as 'svchost.exe' for persistence, and uses custom and repurposed libraries for various functionalities like keylogging, audio capture, and screen capture. Nazar's droppers, built with Chilkat's 'Zip2Secure', are often misidentified by antivirus software. A notable feature is EYService, a passive backdoor listening on UDP port '1234', enabling commands like ping response, victim info requests, and file downloads. Additionally, it uses a packet sniffer for potentially sophisticated command-and-control activities. The report, however, does not specify targeted countries or sectors.
read more about Nazar APT's Complex Cyber Toolkit: From Keylogging to Passive Backdoors