Skip to content

Malware

homefry

a 64-bit Windows password dumper/cracker that has previously been used in conjunction with AIRBREAK and BADFLICK backdoors.

homefry is a Windows malware family operated by Leviathan.

Background

A 64-bit Windows credential dumper and cracker that has been deployed alongside the AIRBREAK and BADFLICK backdoors in past operations. A portion of its strings are obscured using XOR x56. It supports as many as two command-line arguments: one that prints cleartext credentials per login session, and another that prints cleartext credentials together with NTLM hashes and the malware version for each login session.


Source: Malpedia (Fraunhofer FKIE).