Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

December 10th, 2012, 16:11 GMT · By

BLOG

Exforel Backdoor Implemented at NDIS Level to Be More Stealthy

SHARE:

Adjust text size:


Functionality diagram of Exforel malware Enlarge picture - Functionality diagram of Exforel malware
Security researchers from Microsoft’s Malware Protection Center have identified a variant of the Exforel backdoor malware, VirTool:WinNT/Exforel.A, that’s somewhat different from other malicious elements of this kind.

That’s because the backdoor is implemented at the Network Driver Interface Specification (NDIS) level.

Since Exforel.A implements a private TCP/IP stack and hooks NDIS_OPEN_BLOCK for the TCP/IP protocol, the backdoor TCP traffic is diverted to the private TCP/IP stack and then delivered to the backdoor.

This makes this variant of the malware more low-level and stealthy because there is no connecting or listening port. Furthermore, the backdoor traffic is invisible to user-mode applications.

According to experts, this particular version of Exforel – which can download, upload, and execute files, and rout TCP/IP packets – is used in a targeted attack against a particular organization.

TELL US WHAT YOU THINK:

1,628 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hackers Encrypt Australian Medical Center Data, Demand $4,000 (€3,100) Ransom

Searching for “Windows Android Drivers” Can Lead You to Malware-Laden Sites

Malware Disguised as Trend Micro Product Spreads Bitcoin Miner

Necurs Malware Infects over 83,000 Machines in November 2012, Microsoft Says

Malware Alert: Microsoft Windows 8 Pro Anytime Upgrade Purchased via PayPal

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM