SeedWorm Malware Campaign: Unveiling the LisfonService Backdoor Variants
- Actor Motivations: Exfiltration
- Attack Vectors: Backdoor,Downloader,Malware
- Attack Complexity: Medium
- Threat Risk: Unknown
Threat Overview
The provided report outlines the activities of a malware campaign leveraging the SeedWorm backdoor, specifically through variants of a program named LisfonService. These variants were developed and deployed using PowerShell to download and execute a malicious program, 'muddy', across targeted systems. Notably, the campaign utilizes filenames such as svchosts.exe and lisfon.exe to obscure its malicious intent.
Extracted IOCs
- 51ac160f7d60a9ce642080af0425a446fb25b7067e06b3a9a8ec2f777836efd3
- 5723f425e0c55c22c6b8bb74afb6b506943012c33b9ec1c928a71307a8c5889a
- 58972b27b7dc40494e715c2f39a1bcee4d8c18da6bcc3e22785496cca2cee1a0
- 6f8226d890350943a9ef4cc81598e0e953d8ba9746694c0b7e3d99e418701b39
- 9262bf6be648e1b15850a776fe4e393250d74afdf911e94ae07718f8ad4d1664
- bf696397784b22f8e891dd0627dce731f288d14d4791ac5d0a906bc1cbe10de6
- c514c3f293f0cb4c23662a5ab962b158cb97580b03a22b82e21fa3b26d64809c
- f1f11830b60e6530b680291509ddd9b5a1e5f425550444ec964a08f5f0c1a44e
- 31[.]171.154.67
- 46[.]99.148.96
- 78[.]129.139.148
- 78[.]129.222.56
- 79[.]106.224.203
Tip: 13 related IOCs (5 IP, 0 domain, 0 URL, 0 email, 8 file hash) to this threat have been found.
Overlaps
Source: SOCRadar - January 2023
Detection (two cases): 6f8226d890350943a9ef4cc81598e0e953d8ba9746694c0b7e3d99e418701b39, c514c3f293f0cb4c23662a5ab962b158cb97580b03a22b82e21fa3b26d64809c
Source: Picussecurity - March 2022
Detection (four cases): 51ac160f7d60a9ce642080af0425a446fb25b7067e06b3a9a8ec2f777836efd3, 5723f425e0c55c22c6b8bb74afb6b506943012c33b9ec1c928a71307a8c5889a, bf696397784b22f8e891dd0627dce731f288d14d4791ac5d0a906bc1cbe10de6, f1f11830b60e6530b680291509ddd9b5a1e5f425550444ec964a08f5f0c1a44e
Source: Trend Micro - June 2019
Detection (four cases): 31[.]171.154.67, 46[.]99.148.96, 78[.]129.139.148, 79[.]106.224.203
Source: Kaspersky - April 2019
Detection (one case): 78[.]129.222.56
Source: Symantec - December 2018
Detection (five cases): 31[.]171.154.67, 46[.]99.148.96, 78[.]129.139.148, 78[.]129.222.56, 79[.]106.224.203
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
SeedWorm Malware Campaign
A malware campaign known as "SeedWorm" has been detected targeting computer systems. Attackers are using a backdoor program called "LisfonService" alongside system scripts to infect computers.
The alert identifies the activity as part of the SeedWorm campaign.
The primary goal is to infect systems with a backdoor, granting the attackers unauthorized, hidden access. Once inside, they use techniques to avoid detection, communicate with their own servers, and potentially steal sensitive data.
Organizations must keep their software and antivirus programs updated, block the specific internet addresses associated with the attack, and limit users' ability to install unapproved software. Individuals should be highly cautious when opening email attachments and should avoid downloading files from untrusted websites.
The report classifies the severity of the threat as "Medium."