Regin Malware (aka Prax or QWERTY) consists of a trojan and a backdoor that are widely customizable to fit the target. The platform excels at remaining undetected and obfuscating its indicators of compromise. Regin is a modular platform, reminiscent of Flame, Duqu, and stuxnet. The Regin backdoor is a five stage modular component and each stage after the first is hidden and encrypted. After each successful installation of a stage, the next stage is decrypted and installed. Each piece provides as little information as possible about the total component. If any stage fails then the installation terminates.
Saturday, August 25, 2018
Regin Malware, 3 Minute Profile
Labels:
duqu,
reginmalware,
stuxnet
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment