216.73.217.22

The Dark Knight Returns: Joker malware analysis

· Published 03/10/2024 14:43 · Modified 03/10/2024 15:21

Export JSON

Essential information

Published
03/10/2024 14:43
Modified
03/10/2024 15:21
Tags
2024-10-03 apt41 cloud services command and control dns tunneling domain fronting evasion social media steganography
Related entities
8 observables, 1 intrusion sets (apt), 6 techniques (mitre)

Description

The report details sophisticated (C2) techniques employed by the threat group. uses custom malware and legitimate tools to maintain persistent access to compromised networks while evading detection. Key techniques include , , and to hide C2 traffic. The group also leverages and platforms as C2 channels. continually evolves their tactics to bypass security controls, making attribution and detection challenging. The report provides technical details on 's C2 infrastructure and recommendations for defending against their techniques.

External references