SierraCharlie
Description
(Novetta) SierraCharlie is a spreader that appears to target RDP as its vector for propagation. Novetta has not spent a significant amount of time investigating the SierraCharlie family before publication, but the following characteristics of the malware family are known:
- The random IP generation code found in both SierraJuliett-MikeOne and SierraBravo can be found within SierraCharlie
- SierraCharlie, structurally speaking, is heavily object oriented (C++)
- The suicide script within SierraCharlie is consistent with other Lazarus Group malware families
- The propagation mechanism appears to focus on RDP
- At least one sample identifies the malware’s program name as “RDPBForce”
- At least two samples have two distinct version information entries with in the resource section with one entry in English and the other in Korean.
Names
Name |
---|
SierraCharlie |
Category
Malware
Type
- Loader
- Worm
Information
Other Information
Uuid
48f2f3da-c0d2-49f9-b71a-a9560fd3b528
Last Card Change
2020-04-20