Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware down_new

down_new

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

Down_new is a Windows downloader associated with the Bronze Butler actor that retrieves and executes additional malware from remote servers. It serves as an initial foothold, paving the way for more advanced tools within campaigns. Timely detection of its outbound traffic can thwart subsequent stages of compromise.

Enhanced Description

Down_new is a Windows‑based downloader first identified by Trend Micro in November 2019 and has been linked to the Bronze Butler threat actor family since at least that time. As its name suggests, Down_new’s primary function is to fetch additional malicious components from remote hosts and execute them locally. The malware typically establishes HTTP or HTTPS connections to a command and control (C2) server, retrieves executable files or compressed payloads, and then runs the downloaded content to continue the compromise. Its traffic patterns are usually indistinguishable from legitimate web browsing, making detection difficult unless the specific download URLs or file hashes are known. Down_new’s use by Bronze Butler indicates that it serves as a delivery mechanism for more sophisticated exploits or credential‑stealing modules tailored to a target. While no elaborate post‑exploitation features have been documented for this variant itself, its role in provisioning advanced malware suggests a broader operational chain involving additional backdoors, data exfiltration tools, and lateral movement utilities. Because the downloader remains lightweight and modular, it can be re‑used across multiple campaigns with minimal changes to evade detection. The limited public information on Down_new—primarily a single Trend Micro report and lack of comprehensive code analysis—means that many technical details, such as persistence mechanisms or evasion techniques, remain unknown. Defenders should therefore treat it as a generic downloader capable of delivering more dangerous payloads and apply broad defensive measures against anomalous download activity.

Key Capabilities

  • Downloads malicious payloads via HTTP/HTTPS
  • Executes downloaded binaries or scripts on the victim system
  • Obfuscates communication to blend with legitimate web traffic
  • Can be configured to establish persistence through registry run keys or scheduled tasks

ATT&CK Techniques

T1105
T1071.001
T1059

Recommended Actions

  • Deploy network monitoring tools to detect outbound connections to known C2 IPs or domains used by Down_new.
  • Use hash‑based signature rules matching identified download URLs and payload signatures in endpoint protection products.
  • Implement application whitelisting to block execution of unknown binaries downloaded at runtime.
  • Patch and harden web browsers and related plugins to mitigate drive‑by compromise techniques
  • Maintain an up‑to‑date database of known Bronze Butler infrastructure and incorporate it into threat intel feeds.

Suggested Tags

Downloader
Bronze Butlert
Malware
Windows
Command & Control

Confidence Assessment

The available data on Down_new comes from a single vendor report with no disclosed code samples or detailed behavioral analysis, providing moderate confidence in its basic function as a downloader linked to Bronze Butler. Significant gaps remain regarding persistence mechanisms, post‑exploitation modules, and variant variants, limiting the depth of technical characterization.

Description

down_new is a downloader that has been used by BRONZE BUTLER since at least 2019.(Citation: Trend Micro Tick November 2019)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.