HOPLIGHT Spyware Trojan
HOPLIGHT is a newly observed spyware trojan attributed to the Hidden Cobra advanced persistent threat group.
Summary
HOPLIGHT is a newly observed spyware trojan attributed to the Hidden Cobra advanced persistent threat group.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication it is unclear how HOPLIGHT is delivered, although Hidden Cobra have previously used sophisticated spear phishing campaigns to distribute their tools.
HOPLIGHT consists of nine individual files, with seven of these files acting as proxies to disguise its activity and mask command and control communications using valid public SSL certificates. Beneath these layers of obfuscation, the eighth file uses another SSL certificate to create a secure connection before collecting sensitive information, including financial credentials and passwords. The ninth file is then used to extract the information using a separate outbound connection. HOPLIGHT can also create and alter registry keys, spawn and terminate processes and alter files.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 5 November 2020 2:37 pm