Names | Slingshot | |
Category | Malware | |
Type | Loader | |
Description | (Kaspersky) While analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file system, which is usually the sign of an advanced APT actor. This turned out to be a malicious loader internally named ‘Slingshot’, part of a new, and highly sophisticated attack platform that rivals Project Sauron and Regin in complexity. The initial loader replaces the victim´s legitimate Windows library ‘scesrv.dll’ with a malicious one of exactly the same size. Not only that, it interacts with several other modules including a ring-0 loader, kernel-mode network sniffer, own base-independent packer, and virtual filesystem, among others. Following infection, Slingshot would load a number of modules onto the victim device, including two huge and powerful ones: Cahnadr, the kernel mode module, and GollumApp, a user mode module. The two modules are connected and able to support each other in information gathering, persistence and data exfiltration. | |
Information | <https://securelist.com/apt-slingshot/84312/> <https://s3-eu-west-1.amazonaws.com/khub-media/wp-content/uploads/sites/43/2018/03/09133534/The-Slingshot-APT_report_ENG_final.pdf> | |
Malpedia | <https://malpedia.caad.fkie.fraunhofer.de/details/win.slingshot> |
Last change to this tool card: 24 April 2021
Download this tool card in JSON format
Previous: SLICKSHOES
Next: Sliver
Changed | Name | Country | Observed | ||
APT groups | |||||
Slingshot | [Unknown] | 2012 |
1 group listed (1 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |