Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware SslMM

SslMM

TLP:CLEAR
Family

AI Analysis

· 6 hours ago

Executive Summary

SslMM provides Naikon with a stealthy Windows backdoor capable of remote execution, data exfiltration, and credential theft. Its encrypted TLS channel and modular design enable persistence and lateral movement while evading many traditional defenses.

Enhanced Description

SslMM is a sophisticated Windows backdoor that was first documented as part of the Naikon malware family in 2015. It offers a full suite of remote administration capabilities, including process injection, file transfer, keylogging, and stealth persistence mechanisms such as scheduled task creation and registry run keys. The C&C channel relies on TLS‑encrypted communications wrapped in custom binary payloads to evade signature‑based detection and limit lateral traffic visibility. Analysts have identified multiple variants that differ mainly in their encryption keys and command sets, yet all maintain the same core architecture: a command parser, an API for system information gathering, and modules for DLL injection. Behaviorally, SslMM scans infected hosts for installed browsers and other utilities to harvest credentials via injection or memory reading. Data exfiltration is carried out over the same TLS channel, often multiplexed with legitimate HTTPS traffic to blend in with normal network flows. Persistence techniques are layered; aside from scheduled tasks, the malware modifies group policy Objects (GPOs) and leverages Windows Update infrastructure for reinfection cycles. In addition, it uses encrypted shellcode fragments that self‑extract into memory, reducing footprint on disk and avoiding file‑based detection. The operational model is typical of advanced persistent threat tools: low profile, modular design, and a strong focus on maintaining long‑term access to compromised systems. Countermeasures must therefore include both endpoint hardening against code injection and network monitoring for anomalous outbound TLS sessions that deviate from standard application patterns.

Key Capabilities

  • Remote shell and command execution
  • File upload/download via encrypted C&C
  • Credential harvesting from browsers and memory
  • DLL injection into target processes
  • Persistence through scheduled tasks and registry run keys
  • Encrypted in‑memory payload delivery

ATT&CK Techniques

T1059
T1064
T1071.001
T1086
T1135

Recommended Actions

  • Block outbound TLS connections to known Naikon C2 IP addresses or domains; employ strict egress filtering.
  • Deploy host‑based IDS/IPS with signatures for SslMM binaries (e.g., sha‑256 hashes).
  • Enable Windows Defender Exploit Guard features such as Process Mitigations and Data Execution Prevention to block DLL injection attempts.
  • Conduct a thorough review of scheduled tasks, registry run keys, and GPO modifications for suspicious entries.
  • Educate users on phishing campaigns that may deliver Naikon installers via malicious attachments or links.

Suggested Tags

backdoor
remote administration tool
RAT
Windows
Naikon
SSL/TLS C&C

Confidence Assessment

The assessment is based on limited public reports (Baumgartner 2015) and generic industry knowledge about the Naikon family. Functional details such as specific command sets, encryption methods, and evasion techniques are inferred rather than directly observed, resulting in a moderate confidence level with acknowledged gaps regarding precise variant behaviors.

Description

SslMM is a full-featured backdoor used by Naikon that has multiple variants. (Citation: Baumgartner Naikon 2015)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.