Skip to content

Malware

TONEDEAF

TONEDEAF is a backdoor that communicates with Command and Control servers using HTTP or DNS.

TONEDEAF is a Windows malware family operated by APT34.

Background

TONEDEAF is a backdoor that reaches its Command and Control servers over HTTP or DNS. Its command set covers gathering system information, uploading and downloading files, and running arbitrary shell commands. Upon running, this TONEDEAF variant wrote encrypted data into two temporary files – temp.txt and temp2.txt – in the same directory from which it executed.


Source: Malpedia (Fraunhofer FKIE).