Thursday, April 17, 2025
HomeBackdoorIron Cybercrime Group Distributing New Powerful Backdoor with Strong Evasion Techniques

Iron Cybercrime Group Distributing New Powerful Backdoor with Strong Evasion Techniques

Published on

SIEM as a Service

Follow Us on Google News

Newly discovered powerful & previously unknown backdoor using HackingTeam’s leaked Remote Control System (RCS) code to infect the thousands of victim around the world.

This backdoor is created by Iron Cybercrime Group who is behind the recently dicovered Iron ransomware that infected various countries victims in past year.

Also, Iron Cybercrime Group actively developing and infecting victims with various type of cyber threats such as backdoor, crypto-miners, and ransomware for  Windows, Linux and Android platforms.

- Advertisement - Google News

Further analysis revealed that this backdoor contains a source code of HackingTeam’s Remote Control System hacking tool also they used  IronStealer and Iron ransomware is a function with this backdoor.

Iron Cybercrime Group Backdoor working Function

This powerful backdoor employing the various advance technique to evade the detection and maintain its persistence within the infected system.

Initially, it drops malicious chrome extension in %appdata% folder and extracts the malicious code to schedule the task to execute its malicious VBS  script.

Later it Drops backdoor dll to %localappdata%\Temp\\<random>.dat and check the OS version for further infection.

As we already saw that this backdoor using two other malware functions that developed by the HackingTeam cyber criminals and this backdoor also employing the evasion techniques such as Anti-VM.

Also, it can able to detect the Cuckoo Sandbox, VMWare product & Oracle’s VirtualBox and using its Anti-VM function to evade the detection.

Iron Backdoor using dynamically call external library function by obfuscated the function name that gives more pain for an analyst to perform static analysis.

According to intezer, A patched version of the popular Adblock Plus chrome extension is used to inject both the in-browser crypto-mining module (based on CryptoNoter) and the in-browser payment hijacking module.

also, it checks the anti-virus software  360 SafeGuard or 360 Internet Security by reading the registry key. if it found the AV software then it using hardcoded root CA certificate on the victim’s workstation to install the rogue malware.

This Fake CA certificate signed the binary that makes backdoor look legitimate. researchers suspect that the Team behind this backdoor operates it from China because Searches for wallet file names in Chinese on victims’ workstations and it Won’t install persistence if Qhioo360(popular Chinese AV) is found.

Also Read:

Malicious Chrome and Edge Browser Extension Deliver Powerful Backdoor & RAT to Spy Victims PC

Turla Mosquito Hacking Group Exploiting Backdoor Using Metasploit To Compromise the Target System

Malicious Payload Evasion Techniques to Bypass Antivirus with Advanced Exploitation Frameworks

Hackers Increasing the use of “Command Line Evasion and Obfuscation” to Spread Advance Level Threats

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Harvest Ransomware Attack: Stolen Data Now Publicly Disclosed

French fintech leader Harvest SAS has become the latest high-profile victim of a sophisticated ransomware attack,...

Critical Erlang/OTP SSH Vulnerability Allow Hackers Execute Arbitrary Code Remotely

A major security flaw has been uncovered in the widely used Erlang/OTP SSH implementation,...

Chinese Hacker Group Mustang Panda Bypass EDR Detection With New Hacking Tools

The China-sponsored hacking group, Mustang Panda, has been uncovered by Zscaler ThreatLabz to employ...

CISA Warns of Potential Credential Exploits Linked to Oracle Cloud Hack

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a public warning following reports...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Agent Tesla Malware Uses Multi-Stage Attacks with PowerShell Scripts

Researchers from Palo Alto Networks have uncovered a series of malicious spam campaigns leveraging...

Beware! Online PDF Converters Tricking Users into Installing Password-Stealing Malware

CloudSEK's Security Research team, a sophisticated cyberattack leveraging malicious online PDF converters has been...

Chinese Hackers Unleash New BRICKSTORM Malware to Target Windows and Linux Systems

A sophisticated cyber espionage campaign leveraging the newly identified BRICKSTORM malware variants has targeted...