#NACHOCHEESE

Malware/Tool

2018-10-03 • APT38 Un-usual Suspects

NACHOCHEESE is an APT38 command-line tunneler used to provide shell access to compromised systems. Operators supply delimited command-and-control IP addresses or domain names through its command line, allowing the tool to relay communications across a victim environment. In a documented SWIFT intrusion architecture, NACHOCHEESE sat between the public command-and-control server and an active CHEESETRAY backdoor, helping reach a passive CHEESETRAY instance on a segmented SWIFT Alliance Application Server. Some builds contained poorly translated Russian-language strings that were assessed as likely false flags intended to misdirect investigators.

Tagged Reports

« Back