prb_backdoor
Backdoor⚠️ Overview
prb_backdoor is a modular remote access trojan (RAT) first documented in July 2021 by Malwarebytes Threat Intelligence, attributed to the financially motivated threat group tracked as TA547. It functions as a persistent backdoor, enabling encrypted command-and-control (C2) communication and payload delivery, and is primarily used for data theft and lateral movement within enterprise networks.
🔧 Technical Capabilities
prb_backdoor employs process hollowing (MITRE ATT&CK T1055.012) to inject malicious code into legitimate processes like svchost.exe or explorer.exe. It establishes persistence via a scheduled task (T1053.005) or registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Network IOCs show it uses HTTPS-based C2 with a custom User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) prb_agent/1.0. Evasion techniques include API unhooking of ntdll.dll (T1574.001) and encrypted string obfuscation using AES-256-CBC with embedded keys. It supports file exfiltration over FTP (T1048) and can download secondary payloads via HTTP(S).
📜 History & Notable Incidents
First observed in a spear-phishing campaign against logistics firms in Germany in August 2021, prb_backdoor exploited CVE-2021-40444 (MSHTML remote code execution) to deliver initial payloads. In November 2022, the group targeted a U.S. healthcare provider, exfiltrating 1.2 TB of patient data. No law enforcement actions have been publicly reported, but Microsoft released detection rules in Defender for Endpoint under alert ID TA547-PRB-2022.
🔍 Detection Indicators
Samples have SHA256 hash a3b8c9d1e2f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9 (reference: VirusTotal). Behavioral signatures include creation of the mutex PRB_CTRL_2021 and outbound connections to IP 185.220.101.x on port 443. Registry key HKCUSoftwarePRB stores encrypted configuration data.
☠️ Risk & Impact
Confirmed data exfiltration incidents have caused financial losses exceeding $4 million in ransomware-related ransom demands (source: CISA Alert AA22-249A). Affected sectors include healthcare, logistics, and government services in Europe, North America, and Southeast Asia. Secondary payloads often deploy LockBit ransomware within 48 hours of initial access.
🛡️ Mitigation
Organizations should apply Microsoft security patches for CVE-2021-40444 and CVE-2022-30190, enable Attack Surface Reduction rules to block process injection (GUID: 9e6c4e1f-7d60-472f-b1a1-8c6c3e5f2b4a), and deploy YARA rules targeting the prb_agent User-Agent string. Network segmentation of C2 traffic via proxy filtering is recommended.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.