#Brambul

Malware/Tool

2018-05-29 • HIDDEN COBRA – Joanap Backdoor Trojan and Brambul Server Message Block Worm

It spreads over Windows networks by exploiting the SMB vulnerability also used by WannaCry and by attempting to brute-force SMB logins. A related dropper installs Brambul alongside the Joanap remote-access tool. One analyzed routine created and launched lsasvc.exe, accessed shared folders with administrative credentials, collected the host name, and established persistence by adding a WindowsUpdate value under the current user’s Run registry key. U.S. government reporting associated Brambul infrastructure with maintaining access to victim networks and enabling network exploitation.

Tagged Reports

« Back