Neue Windows-Backdoor BITSLOTH nutzt BITS für heimliche Kommunikation aus

Teilen:

Cybersecurity researchers have discovered a previously undocumented Windows backdoor that leverages a built-in feature called Background Intelligent Transfer Service (BITS) as a command-and-control (C2) mechanism.

The newly identified malware strain has been codenamed BITSLOTH by Elastic Security Labs, which made the discovery on June 25, 2024, in connection with a cyber attack targeting an unspecified Foreign Ministry of a South American government. The activity cluster is being tracked under the moniker REF8747.

“The most current iteration of the backdoor at the time of this publication has 35 handler functions including keylogging and screen capture capabilities,” security researchers Seth Goodwin and Daniel Stepanic said. “In addition, BITSLOTH contains many different features for discovery, enumeration, and command-line execution.”

It’s assessed that the tool – in development since December 2021 – is being used by the threat actors for data gathering purposes. It’s currently not clear who is behind it, although a source code analysis has uncovered logging functions and strings that suggest the authors could be Chinese speakers.

Another potential link to China comes from the use of an open-source tool called RingQ. RingQ is used to encrypt the malware and prevent detection by security software, which is then decrypted and executed directly in memory.

In June 2024, the AhnLab Security Intelligence Center’s (ASEC) revealed that vulnerable web servers are being exploited to drop web shells, which are then leveraged to deliver additional payloads, including a cryptocurrency miner via RingQ. The attacks were attributed to a Chinese-speaking threat actor.

The attack is also notable for the use of STOWAWAY to proxy encrypted C2 traffic over HTTP and a port forwarding utility called iox, the latter of which has been previously leveraged by a Chinese cyber espionage group dubbed Bronze Starlight (aka Emperor Dragonfly) in Cheerscrypt ransomware attacks.

BITSLOTH, which takes the form of a DLL file (“flengine.dll”), is loaded by means of DLL side-loading techniques by using a legitimate executable associated with Image-Line known as FL Studio (“fl.exe”).

“In the latest version, a new scheduling component was added by the developer to control specific times when BITSLOTH should operate in a victim environment,” the researchers said. “This is a feature we have observed in other modern malware families such as EAGERBEE.”

A fully-featured backdoor, BITSLOTH is capable of running and executing commands, uploading and downloading files, performing enumeration and discovery, and harvesting sensitive data through keylogging and screen capturing.

It can also set the communication mode to either HTTP or HTTPS, remove or reconfigure persistence, terminate arbitrary processes, log users off from the machine, restart or shutdown the system, and even update or delete itself from the host. A defining aspect of the malware is its use of BITS for C2.

“This medium is appealing to adversaries because many organizations still struggle to monitor BITS network traffic and detect unusual BITS jobs,” the researchers added.

Ravie Lakshmanan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:52 am, Juni 29, 2025
Wetter-Symbol 20°C
L: 19° | H: 20°
klarer Himmel
Luftfeuchtigkeit: 81 %
Druck: 1025 mb
Wind: 6 mph NW
Windböe: 7 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:46 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 20°°C 0 mm 0% 7 mph 82 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
20° | 35°°C 0.2 mm 20% 8 mph 67 % 1022 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
22° | 33°°C 0 mm 0% 10 mph 70 % 1017 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
17° | 27°°C 1 mm 100% 12 mph 91 % 1018 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 19°°C 1 mm 100% 14 mph 93 % 1026 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 20°°C 0 mm 0% 5 mph 81 % 1025 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
18° | 19°°C 0 mm 0% 5 mph 82 % 1025 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
22° | 23°°C 0 mm 0% 4 mph 65 % 1025 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
28° | 28°°C 0 mm 0% 4 mph 41 % 1025 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 4 mph 35 % 1023 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
28° | 28°°C 0 mm 0% 0 mph 34 % 1021 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 7 mph 54 % 1022 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 7 mph 63 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,556.04
0.13%
Ethereum(ETH)
€2,074.91
0.45%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.87
0.25%
Solana(SOL)
€127.89
4.59%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.139144
0.60%
Shiba Inu(SHIB)
€0.000010
1.10%
Pepe(PEPE)
€0.000009
2.91%
Nach oben scrollen