APT16__2022__A_detailed_analysis_of_ELMER_Backdoor_used_by_APT16_CYBER_GEEKS.pdf
ID: 090b72ce-9aa9-417a-babf-5f2468f8c518
STIX ID: report--090b72ce-9aa9-417a-babf-5f2468f8c518
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2022-06-02
Last Modified Date: 2022-06-02
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report provides a deep technical dissection of the ELMER backdoor used by APT16, documenting its Delphi implementation, custom multi-stage decryption (AND/XOR/ADD/NOT/bit shifts), API usage, network protocol (HTTP GET/POST over C2 121.127.249.74:443), eight remote commands (file upload/download, process execution, directory/file/process enumeration, exfiltration), and forensic steps (memory dump, Scylla to rebuild IAT). The analysis includes observed IOCs (SHA256 hashes, URLs, User-Agent) and demonstrates how the malware detects proxy settings, enumerates system/process/file data, and exfiltrates information using encoded HTML payloads.
