#PoorWeb

Malware/Tool

2020-03-25 • APT37 复盘分析报告(part2):木马与工具

PoorWeb is a multifunction C++ remote-access Trojan widely used by APT37. It is commonly delivered through malicious HWP documents and gives operators remote file-manipulation capabilities. A variant used in Operation Imitation Game tested a decoy address before resolving its real command-and-control server, which could help probe the execution environment and conceal infrastructure.

Tagged Reports

« Back