#Brambul
Malware/Tool
2015-10-26 • Duuzer back door Trojan targets South Korea to take over computers
It spreads over Windows networks by exploiting the SMB vulnerability also used by WannaCry and by attempting to brute-force SMB logins. A related dropper installs Brambul alongside the Joanap remote-access tool. One analyzed routine created and launched lsasvc.exe, accessed shared folders with administrative credentials, collected the host name, and established persistence by adding a WindowsUpdate value under the current user’s Run registry key. U.S. government reporting associated Brambul infrastructure with maintaining access to victim networks and enabling network exploitation.
-
7
Tagged Reports
-
6
Unique Authors
-
1,585
Active Days