Executive Summary
Okrum is an advanced Windows backdoor linked to the Ke3chang family, facilitating persistent remote access and potential data theft across corporate networks. It embeds encrypted C2 channels within common ports, making network containment challenging. Security teams should prioritize monitoring for anomalous outbound traffic, defensive persistence mechanisms, and unexplained scheduled tasks or services.
Enhanced Description
Okrum is a Windows‐targeted backdoor first identified in December 2016 and later reported by ESET in July 2019 as having strong associations with the Ke3chang malware family. It is designed to maintain persistent remote control over infected systems, leveraging Windows services and scheduled tasks for resilience against deletion or reboot. Once executed, Okrum establishes encrypted command‑and‑control (C2) communications, often via custom socket protocols that embed traffic in common ports such as 80 or 443 to blend with legitimate web traffic. The backdoor’s feature set includes remote shell access, file upload/download capabilities and the ability to execute arbitrary system commands. It can also inject malicious DLLs into native Windows processes, enabling stealthy persistence and execution of additional payloads without direct user interaction. Although the public dataset lacks explicit documentation of credential theft or exfiltration mechanisms, its integration with Ke3chang—which is known for extensive data‑stealing operations—suggests Okrum may be employed as a foothold within larger espionage campaigns targeting corporate networks. Impact-wise, Okrum can grant attackers unfettered lateral movement across an enterprise, allowing them to navigate through administrative shares, gather system inventory and possibly exfiltrate confidential files. Because it remains dormant until instructed by command signals, detection requires vigilant network monitoring for anomalous outbound connections and host‑based behavioral indicators such as unscheduled creation of scheduled tasks or new services. Overall, Okrum exemplifies the modern backdoor paradigm: lightweight, modular code that survives defensive measures through persistence tricks while providing attackers with a flexible remote control interface.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on limited public information, primarily an ESET report linking Okrum to Ke3chang. While the core characteristics—persistent Windows backdoor behavior and encrypted C2—are well‑documented, detailed IOCs such as file hashes, specific persistence mechanisms, or payloads remain unknown. Consequently confidence in granular detection rules is moderate, and further research (e.g., sandbox analysis, network traffic capture) is necessary to fill gaps.
Okrum is a Windows backdoor that has been seen in use since December 2016 with strong links to Ke3chang.(Citation: ESET Okrum July 2019)