Elise is a Windows backdoor associated with the Dragon Fish and Lotus Blossom threat groups and used in cyberespionage activity targeting government organizations and defense contractors. It supports remote command execution, remote shell access, file uploads and downloads, host reconnaissance, and data exfiltration. Elise is related to the Emissary malware family and Operation Lotus Blossom.
Elise has been distributed through malicious Rich Text Format Microsoft Office document lures exploiting CVE-2018-0802 in Microsoft Office Equation Editor. It injects malicious DLLs and communication code into Internet Explorer processes, and variants execute DLL components through the Windows Rundll32 utility. Persistence is established by installing a Windows service or, when service installation fails, using a per-user Registry autostart entry. Some variants modify Internet Explorer and Firefox proxy settings.
Elise collects information about running processes, network adapters, hardware resources, the Windows version, user identity, locale, time zone, and desktop files. It stages harvested data locally, encrypts exfiltrated data with RC4, and transmits data through Base64-encoded cookie values. Defense-evasion behaviors include checks for VMware, analysis tools, suspicious processes, disk names, and MAC addresses; masquerading as a Windows system component; and timestomping created cabinet archives. It can also use a remote shell to delete itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The outcome: no it is not CVE-2017-11882 but rather CVE-2018-0802. CVE-2018-0802? This a second exploit also included in EQNEDT32.EXE which was detected in later December. | Recently we came across an interesting sample which seems to be related to Elise Malware. Elise is tight to the Dragon Fish and Lotus Blossom APT groups... In this blog post, we will dissect the latest version of Elise.
...a persistent spear-phishing campaign that exploited a Microsoft Office flaw (CVE-2012-0158) to distribute a backdoor dubbed Elise (aka Trensil) that's designed to execute commands and read/write files.
CVE-2018-0802 and CVE-2017-11882: Critical memory corruption vulnerabilities in the legacy Microsoft Office Equation Editor (EQNEDT32.EXE) used extensively during “Spring Dragon” campaigns...
CVE-2016-1019: A critical Adobe Flash Player vulnerability exploited through watering hole attacks and spoofed Flash installer sites to deliver the Elise backdoor...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recently we came across an interesting sample which seems to be related to Elise Malware. Elise is tight to the Dragon Fish and Lotus Blossom APT groups... In this blog post, we will dissect the latest version of Elise.
Recently we came across an interesting sample which seems to be related to Elise Malware. Elise is tight to the Dragon Fish and Lotus Blossom APT groups... In this blog post, we will dissect the latest version of Elise.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Advanced malware delivered via an RTF Office lure exploiting Equation Editor vulnerability CVE-2018-0802. It drops and loads a PE file, injects the main payload into IExplorer.exe, performs multiple sandbox evasion checks, establishes persistence via an autostart key, can modify browser proxy settings, execute commands, download/upload data, and collect host reconnaissance data such as CPU, RAM, disk, OS version, username, locale, timezone, SID, tasks, network adapters, and desktop files.
Custom backdoor used by Lotus Blossom, historically delivered via spear-phishing; supports remote command execution, file transfer, and reconnaissance with persistence via registry and other techniques and HTTP-based C2.
Backdoor family historically used by Lotus Blossom prior to switching to Sagerunex.
An earlier custom backdoor used by Lotus Blossom (noted in 2012–2015-era spearphishing campaigns) to establish persistent access for espionage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.