{"id":52700,"date":"2023-07-11T00:00:00","date_gmt":"2023-07-11T00:00:00","guid":{"rendered":"urn:uuid:b41b04e4-4863-3cfb-feee-8abcecd92592"},"modified":"2023-07-11T00:00:00","modified_gmt":"2023-07-11T00:00:00","slug":"hunting-for-a-new-stealthy-universal-rootkit-loader","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/","title":{"rendered":"Hunting for A New Stealthy Universal Rootkit Loader"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Header.jpg\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"latest news,malware,research,cyber threats\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2023-07-11\"> <meta property=\"article:tag\" content=\"malware\"> <meta property=\"article:section\" content=\"latest news\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader.html\"> <title>Hunting for A New Stealthy Universal Rootkit Loader<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\">\n<link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendmicro\/clientlibs\/trendmicro-core-2\/clientlibs\/header-footer.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader.html\"><br \/>\n<meta property=\"og:title\" content=\"Hunting for A New Stealthy Universal Rootkit Loader\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Header.jpg\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Hunting for A New Stealthy Universal Rootkit Loader\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Header.jpg\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"51.303921021808\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"409638652\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"10.25706940874\">\n<div class=\"article-details\" role=\"heading\" readability=\"40.051413881748\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Malware<\/p>\n<p class=\"article-details__description\">In this entry, we discuss the findings of our investigation into a piece of a signed rootkit, whose main binary functions as a universal loader that enables attackers to directly load a second-stage unsigned kernel module.<\/p>\n<p class=\"article-details__author-by\">By: Mahmoud Zohdy, Sherif Magdy, Mohamed Fahmy <time class=\"article-details__date\">July 11, 2023<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-lg-8 col-lg-push-2\"> <\/p>\n<div class=\"richText\" readability=\"37.97525107604\">\n<div readability=\"21.700143472023\">\n<p>In one of our recent threat hunting investigations, we came across an interesting new threat activity cluster that we initially thought was a false positive detection for a Microsoft signed file. However, this turned out to be a novel piece of a signed rootkit that communicates with a large command-and-control (C&amp;C) infrastructure for an unknown threat actor that we are currently tracking and that we believe that is the same threat actor behind the rootkit <a href=\"https:\/\/www.bitdefender.com\/files\/News\/CaseStudies\/study\/405\/Bitdefender-DT-Whitepaper-Fivesys-creat5699-en-EN.pdf\" target=\"_blank\" rel=\"noopener\">FiveSys<\/a>. This malicious actor originates from China and their main victims are the gaming sector in China. Their malware seems to have passed through the Windows Hardware Quality Labs (WHQL) process for getting a valid signature.&nbsp; We reported our findings to Microsoft&#8217;s Security Response Center (MSRC) in June 2023. &nbsp;<\/p>\n<p>The main binary acts as a universal loader that allows the attackers to directly load a second-stage unsigned kernel module. Each second-stage plug-in is customized to the victim machine it\u2019s deployed on, with some containing even a custom compiled driver for each machine. Each plug-in has a specific set of actions to be carried out from the kernel space.<\/p>\n<p>The found variants are composed of eight main clusters based on the&nbsp;extracted vendor specific metadata from the SPC_SP_OPUS_INFO fields in the signatures (<a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/install\/authenticode\" title=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/install\/authenticode\" target=\"_blank\" rel=\"noopener\">Authenticode<\/a>) revealed various publishers that these variants signed on their behalf (Figure 1).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure01.jpg\" alt=\"Figure 1. The number of samples in each cluster\"><figcaption>Figure 1. The number of samples in each cluster<\/figcaption><\/figure>\n<\/p><\/div>\n<div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure02.jpg\" alt=\"Figure 2. The number of signed drivers in 2022 and 2023 using Microsoft portal\"><figcaption>Figure 2. The number of signed drivers in 2022 and 2023 using Microsoft portal<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35.289301310044\">\n<div readability=\"18.82096069869\">\n<p>Malicious actors currently use different approaches to sign their <a href=\"https:\/\/documents.trendmicro.com\/assets\/white_papers\/wp-an-in-depth-look-at-windows-kernel-threats.pdf\" target=\"_blank\" rel=\"noopener\">malicious kernel drivers<\/a>, typically by:&nbsp;<\/p>\n<p>In this blog entry, we will shed some light on a threat that apparently followed the first approach: abusing WHQL to have a valid signature on a malicious driver that can be successfully loaded on recent Windows versions (Figure 3). We will also provide technical details on this newly discovered malware that comes as a standalone kernel driver signed directly by Microsoft, which is an evolving attack vector that has been frequently appearing in today\u2019s malware landscape. Despite how complex is to build such capabilities, it seems that current malicious actors are exhibiting competence and consistent usage of such tools, tactics, and procedures (TTPs), regardless of their final motive and objectives.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure03.jpg\" alt=\"Figure 3. Malware that comes as a standalone kernel driver signed directly by Microsoft\"><figcaption>Figure 3. Malware that comes as a standalone kernel driver signed directly by Microsoft<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.53112033195\">\n<div readability=\"13.941908713693\">\n<h4>Historical WHCP abuses<\/h4>\n<p>Figure 4 shows a timeline for the reported abuses for Windows Hardware Compatibility Program (WHCP) that led to compromises of the Windows kernel trust model. In June 2021, the Netfilter rootkit was <a href=\"https:\/\/www.gdatasoftware.com\/blog\/microsoft-signed-a-malicious-netfilter-rootkit\" target=\"_blank\" rel=\"noopener\">reported<\/a>, after which Microsoft published an advisory detailing that it was used as a means of <a href=\"https:\/\/msrc.microsoft.com\/blog\/2021\/06\/investigating-and-mitigating-malicious-drivers\/\" target=\"_blank\" rel=\"noopener\">geo-location cheating<\/a> within the gaming community in China. Bitdefender then disclosed <a href=\"https:\/\/www.bitdefender.com\/blog\/labs\/digitally-signed-rootkitsare-back-a-look-atfivesys-and-companions\/\" target=\"_blank\" rel=\"noopener\">FiveSys<\/a> in October 2021, a rootkit that was mainly used to target online gamers with the main goal of credential theft and in-game-purchase hijacking. Finally, Mandiant reported the last known abuse that revealed <a href=\"https:\/\/www.mandiant.com\/resources\/blog\/hunting-attestation-signed-malware\" target=\"_blank\" rel=\"noopener\">Poortry malware<\/a>, which had been used in a number of cyberattacks that included ransomware-based incidents.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure04.jpg\" alt=\"Figure 4. A timeline for the reported abuses for WHCP\"><figcaption>Figure 4. A timeline for the reported abuses for WHCP<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.998738965952\">\n<div readability=\"13.713745271122\">\n<h4>Hunting approach for modern rootkits<\/h4>\n<p>Hunting for 64-bit signed rootkits now is not as easy in the days when kernel mode code signing (KMCS) policies mechanisms were introduced as the number of 64-bit signed drivers has increased, as shown in Figure 5. Back then, the volume of signed drivers with at least one detection was much smaller, also the threat actor did not favor it because of the higher development cost for modern kernel rootkits, and the lake of technical capabilities to include kernel rootkits in their malware arsenal or access to the techniques needed to bypass the security defenses added to newer Windows versions. This makes hunting for such threats more difficult, but this does not indicate that such <a href=\"https:\/\/documents.trendmicro.com\/assets\/white_papers\/wp-an-in-depth-look-at-windows-kernel-threats.pdf\" target=\"_blank\" rel=\"noopener\">threats have completely disappeared from today\u2019s malware landscape<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure05.jpg\" alt=\"Figure 5. Total number of signed drivers with more than one detection before and after 2015\"><figcaption>Figure 5. Total number of signed drivers with more than one detection before and after 2015<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div class=\"responsive-table-wrap\" readability=\"10\">\n<p>As shown in Figure 6, we assessed our Windows kernel driver samples based on:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Their signed driver\u2019s signature being revoked or otherwise<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Their having one or more positive detections based on malware search engines, including the VirusTotal malware repository<\/span><\/li>\n<\/ul>\n<p>Table 1 shows how we segregated each set of the threat samples we have gathered:<\/p>\n<p><center><\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody readability=\"4.5\">\n<tr>\n<td width=\"120\" valign=\"top\"><b>Samples set<\/b><\/td>\n<td width=\"604\" valign=\"top\"><b>Description<\/b><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td width=\"120\" valign=\"top\">Set 1<\/td>\n<td width=\"504\" valign=\"top\">Signed drivers that have not been revoked with zero positive detection<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"120\" valign=\"top\">Set 2<\/td>\n<td width=\"504\" valign=\"top\">Signed drivers that have not been revoked with one or more positive detection from different engines<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td width=\"120\" valign=\"top\">Set 3<\/td>\n<td width=\"504\" valign=\"top\">Signed drivers that have been revoked with zero positive detection<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td width=\"120\" valign=\"top\">Set 4<\/td>\n<td width=\"504\" valign=\"top\">Signed drivers that have been revoked with one or more positive detection from different engines<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span class=\"rte-legal-text\">Table 1. Windows kernel driver threat sample sets<\/span><\/center> <\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure06.jpg\" alt=\"Figure 6. Windows kernel driver samples based on their signed drivers being revoked or otherwise, and their having one or more positive detections\"><figcaption>Figure 6. Windows kernel driver samples based on their signed drivers being revoked or otherwise, and their having one or more positive detections<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>Hunting for new samples submissions from set 1 and set 2 for malicious behavior (Figure 7) led us to investigate this emerging samples cluster and the underlying C&amp;C infrastructure serving the second stage plug-ins.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure07.jpg\" alt=\"Figure 7. An increase in the number of kernel driver submissions belonging to sample set 2 from 2020 to May 2022\"><figcaption>Figure 7. An increase in the number of kernel driver submissions belonging to sample set 2 from 2020 to May 2022<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<h4>First stage analysis<\/h4>\n<p>Based on the collected samples from this campaign, we identified two different clusters that share multiple similarities between their samples (Figure 8). We observed a pattern of having some samples obfuscated with VMProtect and newer samples with more functionality signed later without any obfuscation, which indicates that the malicious actor behind these samples is still in the testing and developing phase.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure08-2.jpg\" alt=\"Figure 8. Two different clusters that share multiple similarities \"><figcaption>Figure 8. Two different clusters that share multiple similarities <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"36\">\n<div readability=\"17\">\n<p>Most of the samples are \u201cMicrosoft Windows Hardware Compatibility Publisher\u201d-signed drivers. We provide an analysis below for a sample from the first cluster.<\/p>\n<p>The driver first checks if there is another instance on the driver loaded to memory (Figure 9) by trying to open the symbolic name \u201c\\??\\ea971b87\u201d, which is created by the driver during initialization. If it successfully opened it, the return error code \u201c0FFFFCFC7\u201d from DriverEntry stops the driver from loading. Then, if the driver is not already loaded, it creates a symbolic name \u201c\\??\\ea971b87\u201d and initializes its handler\u2019s functions; it only uses \u201cIRP_MJ_DEVICE_CONTROL\u201d and \u201cIRP_MJ_SHUTDOWN\u201d based on the current variants we had observed (Figures 10 and 11).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure10.png\" alt=\"Figure 9. Checking if driver is already loaded\"><figcaption>Figure 9. Checking if driver is already loaded<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure11.png\" alt=\"Figure 10. Initializing IO handlers\"><figcaption>Figure 10. Initializing IO handlers<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure12.png\" alt=\"Figure 11. Register shutdown notification handler\"><figcaption>Figure 11. Register shutdown notification handler<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34.5\">\n<div readability=\"14\">\n<p>Then, the driver checks whether the binary compilation is a debug build or a release, as shown in Figure 12. In case of a debug build, it prints some debug messages throughout the execution; this indicates that the current samples are still under development and testing. Then, the driver disables the User Account Control (UAC) and Secure Desktop mode by editing the registry and initializes Winsock Kernel (WSK) objects for initiating a network activity with the C&amp;C server (Figure 13).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure13.png\" alt=\"Figure 12. Checking logic if the compilation is a debug build other than a release\"><figcaption>Figure 12. Checking logic if the compilation is a debug build other than a release<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure14.png\" alt=\"Figure 13. Disabling UAC then initializing WSK objects\"><figcaption>Figure 13. Disabling UAC then initializing WSK objects<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure15.png\" alt=\"Figure 14. Hooking the file system stack from the \u201cIRP_MJ_DEVICE_CONTROL\u201d device control handler\"><figcaption>Figure 14. Hooking the file system stack from the \u201cIRP_MJ_DEVICE_CONTROL\u201d device control handler<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"36\">\n<div readability=\"17\">\n<h4>First-stage network initialization<\/h4>\n<p>The first-stage driver is responsible for all network communication with the C&amp;C servers. It initiates all the communication from the kernel space using WSK, a kernel-mode Network Programming Interface (NPI). With WSK, kernel-mode software modules can perform network I\/O operations using the same socket programming concepts that are supported by user-mode Winsock2 (Figure 15).<\/p>\n<p>It uses a Domain Generating Algorithm (DGA) algorithm to generate different domains (Figure 16). If it fails to resolve an address, it connects directly to fallout Ips that are hard coded inside the driver. It connects to the driver on port 80 and creates a TCP socket for communication.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure16.png\" alt=\"Figure 15. WSK-created socket types\"><figcaption>Figure 15. WSK-created socket types<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure17.png\" alt=\"Figure 16. Resolve DNS\"><figcaption>Figure 16. Resolve DNS<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure18.png\" alt=\"Figure 17. Resolve DNS\"><figcaption>Figure 17. Resolve DNS<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure19.png\" alt=\"Figure 18. DNS request from the first-stage driver\"><figcaption>Figure 18. DNS request from the first-stage driver<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure20.png\" alt=\"Figure 19. Connect to C&amp;C server\"><figcaption>Figure 19. Connect to C&amp;C server<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34.5\">\n<div readability=\"14\">\n<p>Then, it periodically connects to the C&amp;C server to get configuration. It has the option to be a kernel driver loader:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">It receives the data from the C&amp;C server byte by byte (Figure 21)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">It decodes and decrypts the received data (Figure 20)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">It loads the received kernel drivers to the memory directly without writing it to the disk (Figure 22)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">It parses the received Portable Executable (PE) file and does all the relocation<\/span><\/li>\n<li><span class=\"rte-red-bullet\">It calls the driver entry point (Figures 23 and 24)<\/span><\/li>\n<\/ul>\n<p>This way, the kernel plug-in will never touch the disk and will be only in memory, which makes it stealthier and enables it to bypass detections.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure21.png\" alt=\"Figure 20. Decoding data received from the C&amp;C server\"><figcaption>Figure 20. Decoding data received from the C&amp;C server<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure22.png\" alt=\"Figure 21. Receiving configuration for stage one\"><figcaption>Figure 21. Receiving configuration for stage one<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure23.png\" alt=\"Figure 22. Resolving the functions address used to load the new received driver\"><figcaption>Figure 22. Resolving the functions address used to load the new received driver<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure24.png\" alt=\"Figure 23. Getting driver entry address\"><figcaption>Figure 23. Getting driver entry address<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure25.png\" alt=\"Figure 24. Calling the driver entry function\"><figcaption>Figure 24. Calling the driver entry function<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<h4>Second-stage plug-ins<\/h4>\n<p>The downloaded second-stage driver is self-signed, as it\u2019s completely loaded by the first-stage loader, bypassing the Windows native driver loader (Figure 25). Hence, there is no need to sign these second-stage variants. It opens the file \u201c<i>C:\\WINDOWS\\System32\\drivers\\687ae09e.sys<\/i>\u201d then reads its data and encodes it (Figure 26). Then, it divides the data into chunks of memory and writes them to registry path \u201c<i>\\Registry\\Machine\\Software\\PtMyMem<\/i>\u201d alongside its size and MD5 (Figures 27 and 28). After that, it deletes the file \u201c<i>C:\\WINDOWS\\System32\\drivers\\687ae09e.sys<\/i>\u201d from the disk (Figure 29).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure26.png\" alt=\"Figure 25. The self-signed driver for the second stage\"><figcaption>Figure 25. The self-signed driver for the second stage<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure27.png\" alt=\"Figure 26. Reading the file\"><figcaption>Figure 26. Reading the file<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure28.png\" alt=\"Figure 27. The file info\"><figcaption>Figure 27. The file info<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure29.png\" alt=\"Figure 28. The encoded file in the registry\"><figcaption>Figure 28. The encoded file in the registry<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure30.png\" alt=\"Figure 29. Deleting the file written to the disk\"><figcaption>Figure 29. Deleting the file written to the disk<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"41\">\n<div readability=\"27\">\n<h4>Achieving persistence<\/h4>\n<p>The first-stage shutdown notification function checks if a kernel plug-in has been received and loaded in memory from the C&amp;C server for cleanup purposes. It also checks the registry key \u201c<i>\\Registry\\Machine\\Software\\PtMyMem<\/i>\u201d if it presents, then it iterates on all its subkeys and decodes the data, writing it to the disk with the \u201c<i>C:\\WINDOWS\\System32\\drivers\\687ae09e.sys<\/i>\u201d path. Finally, it creates a service with the name \u201cBaohuName\u201d that will run when the system starts again.<\/p>\n<p>The first stage alongside the second stage (the plug-in downloaded from the C&amp;C server) work together as part of the attackers\u2019 self-protection and persistence method. This technique, combined with the downloaded kernel plug-in from the C&amp;C server, will be the main persistence mechanism for this driver. The detailed analysis for this specific second stage plug-in is as follows:<\/p>\n<ol>\n<li>The first-stage driver connects to C&amp;C sever to download second-stage driver<\/li>\n<li>The second-stage driver reads the first-stage driver from disk and write it to registry, then deletes it from disk<\/li>\n<li>Then, the first-stage and second-stage drivers are only present in memory<\/li>\n<li>Before rebooting, the first-stage shutdown notification routine is executed<\/li>\n<li>The shutdown routine will read itself from registry, write itself back to disk, and creates a service that starts the next time the system reboots<\/li>\n<\/ol>\n<h4>Defender terminator plug-in<\/h4>\n<p>The main objective of this driver is to stop Windows Defender software. It first disables the anti-spyware detection from the registry key \u201cHKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\Policies\\\\Microsoft\\\\Windows Defender\u201d (Figure 30), disables the \u201cSecurityHealthService\u201d service (Figure 31), and stops antivirus checks (Figure 32).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure32.png\" alt=\"Figure 30. Stopping anti-spyware detection\"><figcaption>Figure 30. Stopping anti-spyware detection<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure33.png\" alt=\"Figure 31. Stopping the \u201cSecurityHealthService\u201d service\"><figcaption>Figure 31. Stopping the \u201cSecurityHealthService\u201d service<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure34.png\" alt=\"Figure 32. Disabling antivirus checks\"><figcaption>Figure 32. Disabling antivirus checks<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35.5\">\n<div readability=\"16\">\n<p>It then adds an entry for all Windows Defender processes in the \u201cImage File Execution Options\u201d registry (Figures 33, 34, and 35), so when any of them crashes, another process will start (Figure 36). The executable that will start is \u201c<i>C:\\\\Users\\\\Administrator\\\\Desktop\\\\111111111.exe,<\/i>\u201d which indicates that these plug-ins are customized, and the threat actor is actively developing new divers as needed. It eventually terminates all Windows Defender processes (Figure 37).<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure35.png\" alt=\"Figure 33. Adds entry to Image File Execution Options\"><figcaption>Figure 33. Adds entry to Image File Execution Options<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure36.png\" alt=\"Figure 34. Debugger value in image file execution\"><figcaption>Figure 34. Debugger value in image file execution<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure37.png\" alt=\"Figure 35. Debugger value in image file execution\"><figcaption>Figure 35. Debugger value in image file execution<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure38.png\" alt=\"Figure 36. Windows Defender processes\"><figcaption>Figure 36. Windows Defender processes<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure39.png\" alt=\"Figure 37. Terminating the process\"><figcaption>Figure 37. Terminating the process<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<h4>Proxy plug-in<\/h4>\n<p>This plug-in is responsible for installing a proxy on the machine and redirecting web browsing traffic to a remote proxy machine. It first edits the Windows proxy configuration <i>\u201chxxp[:]\/\/4dpyplftay8g90qb7l.kkvgsytcw4hsn3g0nc5r[.]xyz:17654\/api\/pac\/PacReback?key=10252\u201d.<\/i><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure40.png\" alt=\"Figure 38. The edited Windows proxy configuration \"><figcaption>Figure 38. The edited Windows proxy configuration <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"38.5\">\n<div readability=\"22\">\n<p>Then, it injects a JavaScript inside the browser that, based on the URL, might redirect it to another server (Figure 40). As of May 31, 2023, the observed script that checks the URL excludes the following suffixes:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">.edu<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.edu:<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.edu\/<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.gov<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.gov:<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.gov\/<\/span><\/li>\n<\/ul>\n<p>If the URL is one of the domains that is being monitored, it will redirect the traffic to the following addresses:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">HTTP will be redirected to \u201c<i>nt32vn1-redyf[.]gj2oydber4xfa6c[.]com[:]10385<\/i>\u201d<\/span><\/li>\n<li><span class=\"rte-red-bullet\">HTTPS will be redirected to \u201c<i>ybqjb6[.]ady4111523[.]com[:]10385<\/i>\u201d<\/span><\/li>\n<\/ul>\n<p>Here are some of the monitored domains:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><i>www[.]68chuanqi[.]com<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>www[.]ooyy[.]com<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>www[.]v8cq[.]com<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>www[.]bairimen[.]com<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>www[.]980cq[.]cn<\/i><\/span><\/li>\n<\/ul>\n<p>It also excludes the following domains (Figure 42):<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><i>www[.]baidu[.]com<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>e[.]so[.]com<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>www[.]sogou[.]com<\/i><\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure41.png\" alt=\"Figure 39. The decode function\"><figcaption>Figure 39. The decode function<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure42.png\" alt=\"Figure 40. The URL filter\"><figcaption>Figure 40. The URL filter<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>On January 6, 2023, we observed that the script had changed and started to exclude all URLs that had the following extensions:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">.edu.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.edu:<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.edu\/<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.js<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.css<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.jpg<\/span><\/li>\n<li><span class=\"rte-red-bullet\">.bmp<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure43.png\" alt=\"Figure 41. The updated URL filter\"><figcaption>Figure 41. The updated URL filter<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure44.png\" alt=\"Figure 42. Excluded domains\"><figcaption>Figure 42. Excluded domains<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"34.5\">\n<div readability=\"14\">\n<p>Also, it stopped to redirect any of the DGA-generated domains and the proxy servers were changed to the following:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">HTTP were now redirected to: <i>103.45[.]162[.]204:10252<\/i>;<\/span><\/li>\n<li><span class=\"rte-red-bullet\">HTTPS were now redirected to: <i>103.45[.]162[.]217:10252<\/i>;<\/span><\/li>\n<\/ul>\n<p>Here are some of the monitored domains:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><i>Angdao[.]com[.]cn<\/i><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><i>www[.]newsensation.com[.]cn<\/i><\/span><\/li>\n<\/ul>\n<p>Based on this, we believe that the attacker is optimizing their filter mechanism to reduce noise.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<h4>Attribution analysis<\/h4>\n<p>Upon analysis, we have discovered that the drivers and the well-known FiveSys rootkit exhibit numerous similarities in terms of functionality, code similarity, infrastructure, and victimology:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">There are similarities in the C&amp;C infrastructure used by both FiveSys and the newly signed drivers.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Both the FiveSys rootkit and the second stage of the signed rootkit are functionality focused on redirecting web browsing traffic to a custom proxy server controlled by the attacker. Additionally, they both have the capability to install a custom root certificate to redirect HTTPS traffic. The primary purpose of the FiveSys rootkit is to monitor and redirect web traffic, but this functionality has evolved and can now be found in the newly signed rootkit, indicating advancements in its capabilities.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The newly signed rootkit shares numerous functions that are identical to those found in FiveSys, such as hooking the file system functions, and the pre-create mini-filter function (Figure 44).<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure45.png\" alt=\"Figure 43. BinDiff output\"><figcaption>Figure 43. BinDiff output<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Figure46.png\" alt=\"Figure 44. Pre-create mini-filter function similarities between the signed rootkit (right) and the FiveSys rootkit (left)\"><figcaption>Figure 44. Pre-create mini-filter function similarities between the signed rootkit (right) and the FiveSys rootkit (left)<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\">\n<div>\n<ul>\n<li><span class=\"rte-red-bullet\">Only Chinese systems have reported instances of FiveSys infections, just like the newly discovered drivers that our sensors have detected exclusively within China. One of the suspected entry points for these infections was a trojanized Chinese game, much like FiveSys.<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div class=\"richText\" readability=\"38.5\">\n<div readability=\"22\">\n<h4>Conclusion<\/h4>\n<p>Malicious actors who are actively seeking high-privilege access to Windows operating systems use techniques that attempt to combat the increased protection that endpoint protection platform (EPP) and endpoint detection and response (EDR) technologies provide users and processes. Because of these added layers of protection, attackers tend to opt for the path of least resistance to get their malicious code running via the kernel layer or even lower levels. This is why we believe that such threats will not disappear from threat actors\u2019 toolkits anytime soon.<\/p>\n<p>Malicious actors will continue to use rootkits to hide malicious code from security tools, impair defenses, and fly under the radar for long periods of time. These rootkits will see heavy use from sophisticated groups that have both the skills to reverse-engineer low-level system components and the required resources to develop such tools. These malicious actors also tend to possess enough financial resources to either purchase rootkits from underground sources or to buy code-signing certificates to build a rootkit. This means that the main danger involving these kinds of rootkits lies in their ability to hide complex targeted attacks that will be used early in the kill chain, allowing an attacker to impair defenses before their actual payloads are launched in victim environments.&nbsp;<\/p>\n<p>We are currently working to make the indicators of compromise (IOCs) available to the public as part of our ongoing efforts.<span>&nbsp;<\/span><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this entry, we discuss the findings of our investigation into a piece of a signed rootkit, whose main binary functions as a universal loader that enables attackers to directly load a second-stage unsigned kernel module. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":52701,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9511,9534,9513,9509],"class_list":["post-52700","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-cyber-threats","tag-trend-micro-research-latest-news","tag-trend-micro-research-malware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hunting for A New Stealthy Universal Rootkit Loader 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hunting for A New Stealthy Universal Rootkit Loader 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-11T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Header.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Hunting for A New Stealthy Universal Rootkit Loader\",\"datePublished\":\"2023-07-11T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/\"},\"wordCount\":2727,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/hunting-for-a-new-stealthy-universal-rootkit-loader.jpg\",\"keywords\":[\"Trend Micro Research : Cyber Threats\",\"Trend Micro Research : Latest News\",\"Trend Micro Research : Malware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/\",\"name\":\"Hunting for A New Stealthy Universal Rootkit Loader 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/hunting-for-a-new-stealthy-universal-rootkit-loader.jpg\",\"datePublished\":\"2023-07-11T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/hunting-for-a-new-stealthy-universal-rootkit-loader.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/hunting-for-a-new-stealthy-universal-rootkit-loader.jpg\",\"width\":2091,\"height\":1535},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hunting-for-a-new-stealthy-universal-rootkit-loader\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Cyber Threats\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-cyber-threats\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Hunting for A New Stealthy Universal Rootkit Loader\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hunting for A New Stealthy Universal Rootkit Loader 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/","og_locale":"en_US","og_type":"article","og_title":"Hunting for A New Stealthy Universal Rootkit Loader 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-07-11T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/g\/hunting-for-a-new-stealthy-universal-rootkit-loader\/UniversalRootkitLoader-Header.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Hunting for A New Stealthy Universal Rootkit Loader","datePublished":"2023-07-11T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/"},"wordCount":2727,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/hunting-for-a-new-stealthy-universal-rootkit-loader.jpg","keywords":["Trend Micro Research : Cyber Threats","Trend Micro Research : Latest News","Trend Micro Research : Malware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/","url":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/","name":"Hunting for A New Stealthy Universal Rootkit Loader 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/hunting-for-a-new-stealthy-universal-rootkit-loader.jpg","datePublished":"2023-07-11T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/hunting-for-a-new-stealthy-universal-rootkit-loader.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/07\/hunting-for-a-new-stealthy-universal-rootkit-loader.jpg","width":2091,"height":1535},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hunting-for-a-new-stealthy-universal-rootkit-loader\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Cyber Threats","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-cyber-threats\/"},{"@type":"ListItem","position":3,"name":"Hunting for A New Stealthy Universal Rootkit Loader"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52700","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52700"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52700\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/52701"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52700"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52700"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}