Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Let’s now look at the kernel exploits (CVE-2020-1054 and CVE-2021-1732) Roshtyak uses to escalate privileges... The kernel exploits target certain unpatched versions of Windows. Specifically, CVE-2020-1054 is only used on Windows 7 systems where the revision number is not higher than 24552. | The subject of this blog post, a backdoor we dubbed Roshtyak, is not your typical piece of malware. Roshtyak is the DLL backdoor used by Raspberry Robin, a worm spreading through infected removable drives.
Let’s now look at the kernel exploits (CVE-2020-1054 and CVE-2021-1732) Roshtyak uses to escalate privileges... the exploit for CVE-2021-1732 runs on Windows 10, with the targeted build number range being from 16353 to 19042. Before exploiting CVE-2021-1732, Roshtyak also scans through installed update packages to see if a patch for the vulnerability is installed. | The subject of this blog post, a backdoor we dubbed Roshtyak, is not your typical piece of malware. Roshtyak is the DLL backdoor used by Raspberry Robin, a worm spreading through infected removable drives.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The subject of this blog post, a backdoor we dubbed Roshtyak, is not your typical piece of malware. Roshtyak is the DLL backdoor used by Raspberry Robin, a worm spreading through infected removable drives.
The subject of this blog post, a backdoor we dubbed Roshtyak, is not your typical piece of malware. Roshtyak is the DLL backdoor used by Raspberry Robin, a worm spreading through infected removable drives.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Using shared sections, it injects its comms module into the address space of the new process. The injected module is executed via APC injection, using NtQueueApcThreadEx.
The injected module is executed via APC injection, using NtQueueApcThreadEx.
Let’s now look at the kernel exploits (CVE-2020-1054 and CVE-2021-1732) Roshtyak uses to escalate privileges.
Roshtyak performs many suspicious registry operations, for example, setting up the RunOnce key for persistence.
Roshtyak spawns (the AMD64 version of) winver.exe and gets the exploit code to run there using the KernelCallbackTable injection method.
Roshtyak is packed in as many as 14 protective layers, each heavily obfuscated and serving a specific purpose.
Roshtyak temporarily masquerades its process as explorer.exe by overwriting FullDllName and BaseDllName in the _LDR_MODULE structure corresponding to the main executable module.
Using shared sections, it injects its comms module into the address space of the new process. The injected module is executed via APC injection, using NtQueueApcThreadEx.
The injected module is executed via APC injection, using NtQueueApcThreadEx.
It starts by calling GetCommandLineA and GetCommandLineW and wiping both of the returned strings.
Roshtyak is able to effectively delete a file by setting FileDispositionInformation or FileRenameInformation in a call to ZwSetInformationFile.
Numerous anti-debugger, anti-sandbox, anti-VM, and anti-emulator checks are sprinkled throughout the layers.
Roshtyak uses many less sophisticated tricks that are commonly found in other malware as well. These include: Hiding threads using ThreadHideFromDebugger
MAC address of the default gateway ( GetBestRoute -> GetIpNetTable ) MAC addresses of all network adapters ( GetAdaptersInfo )
Environment variables ( username , computername , userdomain , userdnsdomain , and logonserver )
Active processes ( NtQuerySystemInformation(SystemProcessInformation) )
Local administrative privileges ... Domain administrative privileges (check for WinAccountDomainAdminsSid / WinAccountDomainUsersSid )
Roshtyak collects a lot of information about each infected victim.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.