Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware SLOWDRIFT

SLOWDRIFT

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

SLOWDRIFT is a backdoor used by the Korean threat actor APT37 targeting academic and strategic organizations in South Korea. It provides remote control, persistence, and exfiltration capabilities while evading standard security defenses. Detection requires vigilant monitoring of encrypted outbound traffic and anomalous scheduling or registry activity.

Enhanced Description

SLOWDRIFT is a sophisticated backdoor weaponized by the APT37 threat group to infiltrate academic institutions and strategic organizations across South Korea. The malware was first identified in a FireEye report dated February 2018, where investigators documented its deployment against educational networks and other high‑value targets. Once a host has been compromised, SLOWDRIFT establishes a persistent foothold by installing a clandestine agent that communicates with the command‑and‑control (C2) server using encrypted channels. The backdoor is built to provide adversaries with remote control capabilities while blending in with legitimate system traffic. It can download additional payloads, exfiltrate sensitive data, and maintain persistence through scheduled tasks or registry modifications. SLOWDRIFT’s stealth tactics include obfuscating its code and leveraging native Windows binaries to evade signature‑based detection. Operationally, the malware operates as a modular trojan that supports several plug‑ins—credential harvesters, keyloggers, and payload delivery agents. APT37 frequently uses SLOWDRIFT to exfiltrate research data from universities, policy analysis from government labs, and strategic documents from defense contractors, thereby supporting their broader espionage objectives.

Key Capabilities

  • Establishes persistent presence on infected hosts
  • Provides command‑and‑control over the backdoor using encrypted channels
  • Downloads additional payloads to expand functionality
  • Exfiltrates captured credentials, keystrokes, and files
  • Implements stealth mechanisms such as code obfuscation and native binary usage

ATT&CK Techniques

T1059
T1078
T1105
T1086

Recommended Actions

  • Deploy network segmentation and monitor for unexpected outbound connections on non‑standard ports
  • Implement host‑based detection rules for scheduled task or registry modifications associated with persistence
  • Use behavioral EDR solutions that flag encrypted command traffic from known malicious IPs
  • Apply application whitelisting to prevent execution of unsigned binaries
  • Enforce least privilege for user accounts to limit lateral movement

Suggested Tags

APT37
backdoor
academic-targeting
South-Korea
cyber-espionage

Confidence Assessment

The analysis is based on a primary FireEye report citing APT37’s use of SLOWDRIFT, which lends moderate confidence to the core facts such as target type and basic capabilities. However, specific technical details like the exact command set, encryption mechanisms, or persistence methods remain partially inferred due to limited publicly available telemetry, leaving gaps in understanding its full operational profile.

Description

SLOWDRIFT is a backdoor used by APT37 against academic and strategic victims in South Korea. (Citation: FireEye APT37 Feb 2018)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.