New BITSLOTH Backdoor Uses Windows BITS for Hidden Messaging

Cybersecurity experts have uncovered a novel and previously unreported backdoor targeting Windows systems, utilizing a native feature known as Background Intelligent Transfer Service (BITS) for its command-and-control (C2) operations.

This newly discovered malware, named BITSLOTH by Elastic Security Labs, was identified on June 25, 2024, during an investigation into a cyber assault against an unnamed South American Foreign Ministry. This threat group is being monitored under the designation REF8747.

Seth Goodwin and Daniel Stepanic, the security researchers behind the discovery, noted, “The latest version of this backdoor boasts 35 handler functions, including capabilities for keylogging and screen capture. BITSLOTH also includes various tools for system discovery, enumeration, and command-line operations.”

The malware, believed to be in development since December 2021, appears to be primarily used for data collection. Although the precise identity of the attackers remains unknown, an analysis of the source code indicates potential ties to Chinese-speaking individuals.

Further suspicion of Chinese origins arises from the use of RingQ, an open-source tool employed to encrypt the malware and evade detection. This tool is then decrypted and executed directly in the system’s memory.

In June 2024, the AhnLab Security Intelligence Center (ASEC) reported that compromised web servers were used to deploy web shells, which facilitated the delivery of additional malicious payloads, including a cryptocurrency miner encrypted with RingQ. These attacks were linked to a Chinese-speaking threat actor.

The malware’s complexity extends to the use of STOWAWAY for encrypting C2 traffic over HTTP and the employment of iox for port forwarding. Notably, iox has been previously associated with the Chinese cyber espionage group Bronze Starlight (also known as Emperor Dragonfly) in their Cheerscrypt ransomware campaigns.

BITSLOTH operates as a DLL file, specifically “flengine.dll,” and is introduced into the system through DLL side-loading via a legitimate Image-Line executable, FL Studio (“fl.exe”).

“Recent updates to the malware include a new scheduling feature that enables it to execute at designated times,” researchers explained. “This behavior is reminiscent of other contemporary malware families such as EAGERBEE.”

As a sophisticated backdoor, BITSLOTH can execute commands, manage file transfers, perform system enumeration, and capture sensitive information through keylogging and screen capture. It can switch between HTTP and HTTPS for communication, manage its persistence, terminate processes, log off users, reboot or shut down systems, and even update or remove itself. Its use of BITS for C2 is particularly notable due to the challenge many organizations face in monitoring and detecting unusual BITS traffic.

More Articles & Posts