Daserf, also known as Muirim and Nioupale, is a custom Windows backdoor used by the cyberespionage group Tick, also tracked as BRONZE BUTLER and REDBALDKNIGHT. It provides remote access through command-and-control connections and supports shell command execution, file downloads and uploads, screenshot capture, and keystroke logging. Daserf has been used in campaigns targeting Japanese technology, engineering, and broadcasting organizations to steal sensitive information, including emails and business documents.
Daserf has been deployed through watering-hole attacks involving compromised Japanese websites and Adobe Flash exploitation, with the Gofarer downloader installing the backdoor. Associated campaigns also used spear-phishing and malicious Office documents, including exploitation of CVE-2014-4114. Daserf uses Mimikatz and Windows Credential Editor for credential theft and conceals collected data in password-protected RAR archives. Its HTTP communications are obfuscated using custom Base64 encoding and RC4 encryption, and later variants use steganography. It masquerades as legitimate software through deceptive file and folder naming, and some samples have been signed with a stolen digital certificate.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Daserf appears to be custom-developed for use in Tick’s cyberespionage campaigns. Once installed, it establishes a remote connection to Tick’s command and control server, providing the attacker with access to the compromised computer.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
“REDBALDKNIGHT’s Daserf Backdoor Now Uses Steganography,” TrendMicro, November 7, 2017
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Cobian RAT obfuscates communications with the C2 server using Base64 encoding... Daserf uses custom base64 encoding to obfuscate HTTP traffic... Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
Cobalt Strike can use Base64, URL-safe Base64, or NetBIOS encoding in its C2 traffic. More_eggs has used basE91 encoding, along with encryption, for C2 communication. Zebrocy has used URL/Percent Encoding on data exfiltrated via HTTP POST requests.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE BUTLER threat profile.
Uses Mimikatz and Windows Credential Editor for credential theft.
Backdoor that uses RC4 to obfuscate HTTP C2 traffic.
Malware that blends in by using file and folder names associated with legitimate software vendors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.