APT41__2019__LOWKEY_Hunting_for_the_Missing_Volume_Serial_ID.pdf
ID: 787c878a-be57-40dc-836b-e8ea6ecb8b6c
STIX ID: report--787c878a-be57-40dc-836b-e8ea6ecb8b6c
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-10-16
Last Modified Date: 2019-10-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye analyzes DEADEYE droppers and the LOWKEY passive backdoor used by APT41, detailing a multi-stage infection chain that employs RC5/RC4 encrypted payloads, a reflective loader, and a user-mode rootkit (NetAgent) to enable covert activation (passive TCP/HTTP listeners), named-pipe communications, remote shell, file operations, and TCP relay; the report includes technical TTPs and numerous indicators (MD5s, derived volume-serial keys, C2 artifacts) and demonstrates methods used to brute-force volume-derived RC5 keys to recover payloads.
