Skip to content

Malware

DeliveryCheck

aka GAMEDAY · CAPIBAR

According to CERT-UA, this malware makes use of XSLT (Extensible Stylesheet Language Transformations) and COM-hijacking.

DeliveryCheck, also known as GAMEDAY, CAPIBAR, is a Windows malware family operated by Turla.

Background

CERT-UA reports that this malware leverages XSLT (Extensible Stylesheet Language Transformations) together with COM-hijacking. What sets it apart is a server-side component, typically deployed on compromised MS Exchange servers as a MOF (Managed Object Format) file via the Desired State Configuration (DCS) PowerShell tool, which converts a legitimate server into a hub for controlling the malware.


Source: Malpedia (Fraunhofer FKIE).