cmd
Malware⚠️ Overview
Cmd is a backdoor trojan first identified by Mandiant in early 2020 as part of the LightBasin (UNC1945) threat group’s arsenal, targeting telecommunications and satellite communications providers. It belongs to the Remote Access Trojan (RAT) category and relies on DNS tunneling for covert command-and-control (C2) communication.
🔧 Technical Capabilities
Cmd propagates via spear-phishing emails with malicious Office documents exploiting CVE-2017-0199 and CVE-2021-40444, followed by a PowerShell payload that deploys the backdoor. Its C2 infrastructure uses public DNS resolvers like 8.8.8.8, encoding data in A, AAAA, and TXT queries to blend with legitimate traffic. Persistence is achieved through scheduled tasks disguised as Windows update routines, while evasion includes process hollowing into svchost.exe, AMSI bypass via reflection, and storing encrypted configuration under HKLMSoftwareMicrosoftCryptography. The backdoor also employs custom packing per campaign to avoid signature detection, and uses a built-in SOCKS proxy to tunnel additional traffic.
📜 History & Notable Incidents
First documented in Mandiant’s 2021 report on LightBasin, Cmd was observed in a campaign targeting a Southeast Asian telecom operator, exfiltrating network diagrams and customer PII. A 2022 incident involved satellite communication providers in India and Japan, where the backdoor remained dormant for months. No law enforcement actions have been announced against UNC1945, which is believed to operate from China.
🔍 Detection Indicators
Indicators include the mutex “Cmd_Global_Mutex,” registry key HKLMSoftwareMicrosoftCryptographyConfig containing base64-encoded configuration, and DNS queries to domains like update-microsoft-dns[.]com. Behavioral signatures include svchost.exe performing excessive DNS lookups to public resolvers and process hollowing detections in EDR logs. No public SHA256 hashes are available due to custom packing, but User-Agent strings from C2 responses often contain “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36” spoofed as Google Chrome.
☠️ Risk & Impact
Cmd enables persistent access for data exfiltration, stealing authentication credentials, network topology, and customer personally identifiable information. The primary impact is on telecommunications and satellite sectors, causing operational disruption and intellectual property theft with estimated remediation costs in the millions of dollars per campaign. Affected organizations also face regulatory penalties for data breaches.
🛡️ Mitigation
Mitigation includes blocking outbound DNS to non-corporate resolvers at the firewall, deploying EDR with behavioral rules for process hollowing and scheduled task anomalies, and patching CVE-2017-0199 and CVE-2021-40444. DNS sinkholing and network segmentation of critical assets can disrupt C2 communications. References: Mandiant’s 2021 LightBasin report; MITRE ATT&CK techniques T1572 (Protocol Tunneling), T1059 (Command and Scripting Interpreter), and T1543 (Scheduled Task/Job).
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.