#TOGREASE

Malware/Tool

2024-11-28 • APT trends report Q3 2024

TOGREASE is an evolved GREASE malware variant used by Kimsuky and installed through the group's ServiceChanger persistence mechanism. It can enable or disable Remote Desktop Protocol access when directed by an operator. Related GREASE versions create backdoor accounts named Guest or IIS_USER for RDP access, reuse code from the public UACME project to bypass User Account Control, and communicate with command-and-control infrastructure in a manner similar to RandomQuery.

Tagged Reports

« Back