Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Tesla’s fourth “master plan” reads like nonsense generated in LLM

Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe

Humanity raises a $13 billion Series F at a valuation of $183 billion

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Researchers warning MyStrodx backdoor using DNS and ICMP triggers for Stealthy Control
Identity

Researchers warning MyStrodx backdoor using DNS and ICMP triggers for Stealthy Control

userBy userSeptember 2, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

September 2, 2025Ravi LakshmananCyberspy/Network Security

MyStrodx Backdoor

Cybersecurity researchers have revealed a new stealthy backdoor called MyStrodx. It comes with a variety of features to capture sensitive data from compromised systems.

“MyStrodx is a typical backdoor implemented in C++ and supports features like file management, port forwarding, reverse shell, socket management, and more,” Qianxin XLAB said in a report published last week. “Compared to a typical backdoor, MyStrodx stands out in terms of stealth and flexibility.”

MyStrodx, also known as Chronosrat, was first recorded last month by Palo Alto Networks Unit 42 in connection with a threat activity cluster called Cl-STA-0969.

Audit and subsequent

Malware stealth comes from obscuring the source code and payload using different levels of encryption, but its flexibility allows you to dynamically enable different features based on your configuration, such as choosing TCP or HTTP for network communication, or Pleantext or AES encryption to protect network traffic.

MyStrodx also supports what is called wake-up mode, which can act as a passive backdoor that can be triggered after receipt of specially created DNS or ICMP network packets from incoming traffic. There is evidence to suggest that malware may have been present since at least January 2024, based on the activation timestamp set in the configuration.

“The value of magic has been verified and MyStrodx establishes communication with C2 [command-and-control] XLAB researchers said, “We use more commands using the specified protocol.

Malware is delivered by droppers using debuggers and virtual machine-related checks to determine whether the current process is being debugged or running within a virtualized environment. Once the verification step is complete, the next stage payload is decrypted. Contains 3 components –

During the day, launchers responsible for launching Chargen Chargen, MyStrodx backdoor components and Busybox

CIS Build Kit

When run, MyStrodx continuously monitors daytime processes and launches immediately if they are not found to be running. The configuration encrypted using the AES algorithm includes information about the C2 server, backdoor type, main and backup C2 ports.

“When the backdoor type is set to 1, MyStrodx enters passive backdoor mode and waits for the activation message,” Xlab said. “If the value of the backdoor type is not 1, MyStrodx is in active backdoor mode, establishing communication with the C2 specified in the configuration, and waiting for the command to be executed.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleKlarna aims to revive its IPO plan and raise $12.7 billion
Next Article Openai, which routes sensitive conversations to GPT-5, introduces parent controls
user
  • Website

Related Posts

Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe

September 2, 2025

An important part of enterprise AI governance

September 2, 2025

Ukrainian Network FDN3 launches massive brute force attacks on SSL VPN and RDP devices

September 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Tesla’s fourth “master plan” reads like nonsense generated in LLM

Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe

Humanity raises a $13 billion Series F at a valuation of $183 billion

WordPress unveils Telex, an experimental AI development tool

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Beyond Compliance: The New Era of Smart Medical Device Software Integration

Unlocking Tomorrow’s Health: Medical Device Integration

Web 3.0’s Promise: What Sir Tim Berners-Lee Envisions for the Future of the Internet

TwinH’s Paves Way at Break The Gap 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.