Dolphin malware discovered by researchers

Share post:

Dolphin, a sophisticated backdoor discovered by ESET researchers, expands the ScarCruft APT group’s arsenal with a wide range of spying capabilities, including monitoring drives and portable devices and exfiltrating files of interest, keylogging and taking screenshots, and stealing credentials from browsers.

Its functionality is restricted to specific targets, to which the backdoor is deployed following an initial compromise with less sophisticated malware. Dolphin makes extensive use of cloud storage services, particularly Google Drive, for command-and-control communication.

The backdoor can exfiltrate files from a path specified in a command, and it actively searches drives for files with interesting extensions and automatically exfiltrates them. In addition, the backdoor gathers basic information about the targeted machine, such as the operating system version, malware version, list of installed security products, username, and computer name.

Following the deployment of the Dolphin backdoor on selected targets, it searches the drives of compromised systems for interesting files and exfiltrates them to Google Drive. And ESET researchers have observed multiple versions of Dolphin since its initial discovery in April 2021, in which threat actors improved the backdoor’s capabilities and attempted to avoid detection.

Dolphin searches all fixed (HDD) and non-fixed (USB) drives, generates directory listings, and exfiltrates files based on their extension. Dolphin can also search for portable devices like smartphones using the Windows Portable Device API.

The sources for this piece include an article in BleepingComputer.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Cyber Security Today, Week in Review for week ending Friday April 19, 2024

On this episode Jen Ellis, co-chair of the Ransomware Task Force, talks about ways of fighting one of the biggest cyber threats to IT d

Cyber Security Today, April 19, 2024 – Police bust phishing rental platform, a nine-year old virus found on Ukrainian computers, and more

This episode reports on a threat actor targeting governments in the Middle East with a novel way of hiding malware is going international

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways