This family of malware is a backdoor that tunnels its connection through a preconfigured proxy. The malware communicates with a remote command and control server over HTTPS via the proxy. The malware installs itself as a Windows service with a service name supplied by the attacker but defaults to IPRIP if no service name is provided during install.
Created: 2026-02-23
Indicatorsは見つかっていない。
このPulseに見つかったCVEはありません。