\
 
BackRefresh Options Favorite

Newly discovered NSA malware is really cool

https://www.techrepublic.com/article/newly-discovered-slings...
Snowy Stock Car Death Wish
  03/16/18
Following infection, Slingshot would load a number of module...
Snowy Stock Car Death Wish
  03/17/18
...
Effete Impressive Theater Stage Really Tough Guy
  03/17/18
...
electric crawly doctorate brethren
  03/17/18
...
mentally impaired private investor mental disorder
  03/17/18


Poast new message in this thread



Reply Favorite

Date: March 16th, 2018 9:19 PM
Author: Snowy Stock Car Death Wish

https://www.techrepublic.com/article/newly-discovered-slingshot-malware-was-hidden-in-routers-for-6-years/

Very impressive. Targets like Kenya, Afghan etc. so def NSA op.

(http://www.autoadmit.com/thread.php?thread_id=3920865&forum_id=1024#35622681)



Reply Favorite

Date: March 17th, 2018 7:22 PM
Author: Snowy Stock Car Death Wish

Following infection, Slingshot would load a number of modules onto the victim device, including two huge and powerful ones: Cahnadr, the kernel mode module, and GollumApp, a user mode module. The two modules are connected and able to support each other in information gathering, persistence and data exfiltration.

The most sophisticated module is GollumApp. This contains nearly 1,500 user-code functions and provides most of the above described routines for persistence, file system control and C&C communications.

Canhadr, also known as NDriver, contains low-level routines for network, IO operations and so on. Its kernel-mode program is able to execute malicious code without crashing the whole file system or causing Blue Screen - a remarkable achievement. Written in pure C language, Canhadr/Ndriver provides full access to the hard drive and operating memory despite device security restrictions, and carries out integrity control of various system components to avoid debugging and security detection.

(http://www.autoadmit.com/thread.php?thread_id=3920865&forum_id=1024#35627900)



Reply Favorite

Date: March 17th, 2018 9:06 AM
Author: Effete Impressive Theater Stage Really Tough Guy



(http://www.autoadmit.com/thread.php?thread_id=3920865&forum_id=1024#35625096)



Reply Favorite

Date: March 17th, 2018 7:24 PM
Author: electric crawly doctorate brethren



(http://www.autoadmit.com/thread.php?thread_id=3920865&forum_id=1024#35627914)



Reply Favorite

Date: March 17th, 2018 7:32 PM
Author: mentally impaired private investor mental disorder



(http://www.autoadmit.com/thread.php?thread_id=3920865&forum_id=1024#35627980)