Punisher Remote Access Trojan
First observed in late 2018, Punisher is a modular, .NET-based remote access trojan. Publicly available on several dark web forums, it can be configured with several capabilities according to the user's wishes.
Summary
First observed in late 2018, Punisher is a modular, .NET-based remote access trojan. Publicly available on several dark web forums, it can be configured with several capabilities according to the user's wishes.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, Punisher is delivered exclusively by the Mjag dropper, although this is likely to change as more threat actors begin using the trojan. Once installed, it will connect to a threat actor specified command and control server before collecting and transmitting system information back to the server. It will also create registry keys to ensure persistence.
Punisher will attempt to collect a range of information, including; credentials, keystrokes, files and IP data. It will also monitor the Task Manager and prevent certain processes from terminating other processes. Newer variants of Punisher will enumerate removable drives and copy themselves to them to aid further propagation.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:51 pm