Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Okrum

Okrum

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

Okrum is an advanced Windows backdoor linked to the Ke3chang family, facilitating persistent remote access and potential data theft across corporate networks. It embeds encrypted C2 channels within common ports, making network containment challenging. Security teams should prioritize monitoring for anomalous outbound traffic, defensive persistence mechanisms, and unexplained scheduled tasks or services.

Enhanced Description

Okrum is a Windows‐targeted backdoor first identified in December 2016 and later reported by ESET in July 2019 as having strong associations with the Ke3chang malware family. It is designed to maintain persistent remote control over infected systems, leveraging Windows services and scheduled tasks for resilience against deletion or reboot. Once executed, Okrum establishes encrypted command‑and‑control (C2) communications, often via custom socket protocols that embed traffic in common ports such as 80 or 443 to blend with legitimate web traffic. The backdoor’s feature set includes remote shell access, file upload/download capabilities and the ability to execute arbitrary system commands. It can also inject malicious DLLs into native Windows processes, enabling stealthy persistence and execution of additional payloads without direct user interaction. Although the public dataset lacks explicit documentation of credential theft or exfiltration mechanisms, its integration with Ke3chang—which is known for extensive data‑stealing operations—suggests Okrum may be employed as a foothold within larger espionage campaigns targeting corporate networks. Impact-wise, Okrum can grant attackers unfettered lateral movement across an enterprise, allowing them to navigate through administrative shares, gather system inventory and possibly exfiltrate confidential files. Because it remains dormant until instructed by command signals, detection requires vigilant network monitoring for anomalous outbound connections and host‑based behavioral indicators such as unscheduled creation of scheduled tasks or new services. Overall, Okrum exemplifies the modern backdoor paradigm: lightweight, modular code that survives defensive measures through persistence tricks while providing attackers with a flexible remote control interface.

Key Capabilities

  • Persistent installation via Windows services and scheduled tasks
  • Encrypted command‑and‑control channel over common ports
  • Remote shell execution and OS command injection
  • File upload/download and DLL injection for auxiliary payloads
  • Potential for data exfiltration and lateral movement

ATT&CK Techniques

T1059
T1071.001
T1055
T1069
T1037

Recommended Actions

  • Block outbound connections to known Okrum C2 domains or IP ranges using firewall rules.
  • Scan for suspicious services, scheduled tasks and registry keys that match patterns from ESET reports.
  • Implement host‑based intrusion detection solutions that flag anomalous DLL injections or PowerShell usage.
  • Conduct regular system integrity checks (e.g., file hash monitoring) for backdoor executables.
  • Apply the latest OS patches to close exploitation vectors that could be leveraged by auxiliary payloads.

Suggested Tags

malware.type.backdoor
windows
ke3chang
remote-access-trojan
persistent
command-and-control
RAT

Confidence Assessment

The analysis is based on limited public information, primarily an ESET report linking Okrum to Ke3chang. While the core characteristics—persistent Windows backdoor behavior and encrypted C2—are well‑documented, detailed IOCs such as file hashes, specific persistence mechanisms, or payloads remain unknown. Consequently confidence in granular detection rules is moderate, and further research (e.g., sandbox analysis, network traffic capture) is necessary to fill gaps.

Description

Okrum is a Windows backdoor that has been seen in use since December 2016 with strong links to Ke3chang.(Citation: ESET Okrum July 2019)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.