logo

APT41__2019__LOWKEY_Hunting_for_the_Missing_Volume_Serial_ID.pdf

ID: 787c878a-be57-40dc-836b-e8ea6ecb8b6c

STIX ID: report--787c878a-be57-40dc-836b-e8ea6ecb8b6c

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-10-16

Last Modified Date: 2019-10-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye analyzes DEADEYE droppers and the LOWKEY passive backdoor used by APT41, detailing a multi-stage infection chain that employs RC5/RC4 encrypted payloads, a reflective loader, and a user-mode rootkit (NetAgent) to enable covert activation (passive TCP/HTTP listeners), named-pipe communications, remote shell, file operations, and TCP relay; the report includes technical TTPs and numerous indicators (MD5s, derived volume-serial keys, C2 artifacts) and demonstrates methods used to brute-force volume-derived RC5 keys to recover payloads.