Skip to content

Malware

ELMER

aka Elmost

ELMER is a non-persistent proxy-aware HTTP backdoor written in Delphi, and is capable of performing file uploads and downloads, file execution, and process and directory listings.

ELMER, also known as Elmost, is a Windows malware family operated by Danti and APT 16.

Background

Written in Delphi, ELMER is a non-persistent, proxy-aware HTTP backdoor that supports uploading and downloading files, running executables, and enumerating processes and directories. It fetches instructions by issuing HTTP GET requests to a hard-coded CnC server and then parsing the server's HTTP responses for an integer string that identifies which command to run.


Source: Malpedia (Fraunhofer FKIE).