Skip to content

Malware

CHEESETRAY

aka CROWDEDFLOUNDER

CHEESETRAY is a sophisticated proxy-aware backdoor that can operate in both active and passive mode depending on the passed command-line parameters.

CHEESETRAY, also known as CROWDEDFLOUNDER, is a Windows malware family operated by Lazarus Group.

Background

CHEESETRAY is an advanced, proxy-aware backdoor whose mode of operation, active or passive, is dictated by the command-line parameters it receives. Among its many features, the backdoor can list files, processes, drivers, and remote desktop sessions; transfer files in both directions; spawn and kill processes; remove files; open a reverse shell; function as a proxy server; and hijack processes. It talks to its C&C server over TCP using a proprietary binary protocol, with the port supplied as a command-line argument.


Source: Malpedia (Fraunhofer FKIE).