A new backdoor named Poison Frog was analyzed by researchers and revealed that the threat group OilRig appeared “sloppy” in their development of it. Kaspersky came across Poison Frog while scanning their archives looking for old OilRig malware after OilRig information was shared over a Telegram channel. Kaspersky found that Poison Frog had an executable that was written in C# which dropped a PowerShell script containing a DNS and HTTP backdoor, executed the script and then deleted it. Several mistakes were made by OilRig in this malware–such as one sample not executing because a command was spelled wrong and dates within the malware was wrong.
By: Dan McNemar It is not a new concept that criminals use the Darknet to