Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Backdoor.Oldrea

Backdoor.Oldrea

TLP:CLEAR
Family

Also known as: Havex

AI Analysis

· 2 months ago

Executive Summary

Backdoor.Oldrea is a modular backdoor used by Dragonfly to target energy companies, distributed via supply chain compromise and including ICS-specific modules. The malware enables persistent access, data exfiltration, and command execution on compromised Windows systems. Its specialized modules pose a significant threat to energy sector security and integrity.

Enhanced Description

Backdoor.Oldrea, also known as Havex, is a sophisticated modular backdoor malware primarily used by the Dragonfly threat actor group to target energy companies since at least 2013. The malware's primary function is to establish a persistent backdoor on compromised Windows systems, enabling the attackers to execute commands, exfiltrate sensitive data, and install additional malicious modules. Notably, Backdoor.Oldrea was distributed via supply chain compromise, exploiting vulnerabilities in software used by the targeted energy sector. The malware includes specialized modules designed to enumerate and map Industrial Control Systems (ICS)-specific systems, processes, and protocols, demonstrating a tailored approach to disrupt and gather intelligence on critical infrastructure. This targeted approach highlights the significant threat posed by Backdoor.Oldrea to the security and integrity of energy sector operations.

Key Capabilities

  • Establishes a persistent backdoor on compromised systems
  • Exfiltrates sensitive data
  • Executes commands remotely
  • Includes ICS-specific modules for enumeration and mapping
  • Spreads via supply chain compromise

ATT&CK Techniques

T1059
T1055
T1190
T1204
T1210

Recommended Actions

  • Implement robust supply chain risk management practices
  • Conduct regular vulnerability assessments and patching
  • Deploy endpoint detection and response tools
  • Monitor network traffic for suspicious activity
  • Enforce least privilege access and network segmentation

Suggested Tags

Backdoor.Oldrea
Havex
Dragonfly
Energy Sector
Supply Chain Compromise
ICS
Modular Malware

Confidence Assessment

Confidence in the available data is moderate to high, based on historical reports from reputable sources such as Symantec and Gigamon. However, analysis gaps exist regarding the current activity and evolution of Backdoor.Oldrea, as well as the full scope of its technical capabilities.

Description

Backdoor.Oldrea is a modular backdoor that used by Dragonfly against energy companies since at least 2013. Backdoor.Oldrea was distributed via supply chain compromise, and included specialized modules to enumerate and map ICS-specific systems, processes, and protocols.(Citation: Symantec Dragonfly)(Citation: Gigamon Berserk Bear October 2021)(Citation: Symantec Dragonfly Sept 2017)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.