Skip to content

Malware

EASYNIGHT

FireEye describes EASYNIGHT is a loader observed used with several malware families, including HIGHNOON and HIGHNOON.LITE.

EASYNIGHT is a Windows malware family operated by APT41.

Background

Per FireEye, EASYNIGHT is a loader seen alongside multiple malware families such as HIGHNOON and HIGHNOON.LITE. It frequently doubles as a persistence mechanism through search order hijacking.

One observed example is a patched bcrypt.dll whose only change is an added import entry, in that case "printwin.dll!gzwrite64", which invalidates the file's signature.


Source: Malpedia (Fraunhofer FKIE).