Hackers may have found an entirely new way to backdoor into Windows systems

Laptop screen with red background and a warning sign in the middle
(Image credit: Pixabay)

A University in Taiwan has been attacked with a previously undocumented Windows backdoor that uses an usual, but not entirely new, method of communication.

Cybersecurity researchers from the Symantec Threat Hunter Team published their findings on Msupedge, which is designed as a dynamic link library (.DLL) with a particularly distinctive feature of communicating with the C2 via DNS traffic.

Msupedge grants its operators the ability to create processes on the target endpoint, download files, sleep for a predetermined time interval, create a temporary file (purpose unknown), and delete that said file.

Missing key details

"The most notable feature of this backdoor is that it communicates with a command-and-control (C&C) server via DNS traffic," the researchers said in their report. “Msupedge uses DNS tunneling for communication with the C&C server. The code for the DNS tunneling tool is based on the publicly available dnscat2 tool. It receives commands by performing name resolution.”

The researchers added that the technique is known, and has been used by “multiple threat actors”. “It is nevertheless something that is not often seen.”

We also don’t know exactly what the threat actors were looking for, or if they found it. We do know that they breached the victim devices through a PHP vulnerability that allows remote code execution (RCE). The vulnerability, tracked as CVE-2024-4577, carries a severity score of 9.8/10, making it a critical flaw.

Other important details are still missing - as it isn't known who the threat actors behind the attack are, or who the victim is (other than it is an unnamed university in Taiwan).

Given the current political climate, we can only speculate that this is the work of a Chinese state-sponsored group running cyber-espionage campaigns, targeting intellectuals and other academia members. Volt Typhoon is one such organization, which was observed in the past, running similar campaigns.

Via TheHackerNews

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Close up of the Linux penguin.
A new Linux backdoor is hitting US universities and governments
China
Chinese hackers develop effective new hacking technique to go after business networks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Juniper VPN gateways targeted by stealthy "magic" malware
Telegram
New Golang malware is hijacking Telegram to help itself spread
Ransomware
Researchers hijack thousands of backdoors thanks to expired domains
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening