Bateleur JavaScript Backdoor
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Bateleur is typically distributed as a malicious Word document in spam campaigns directed at target organisations, but has also been observed being delivered directly to previously compromised devices. Once opened, macros in the document extract an obfuscated JavaScript payload and save it as debug.txt. Bateleur also has anti-VM capabilities, although these are only enabled in certain variants.
Once installed, Bateleur will connect to a command and control server over HTTPS and await instructions. It is able to collect system and user information, execute commands and PowerShell scripts, install secondary malware and upgrade its functionality with additional modules.
Remediation advice
To prevent and detect an infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:38 pm