Cranefly’s new discrete malware for cyberattack campaigns busted

November 1, 2022

A new dropper has been discovered that installs new backdoors and other tools using a specific method to read commands from relatively harmless Internet Information Services (IIS) logs.

The new dropper discreetly infects victims by abusing legitimate tools and infecting them with a form of malware or dropper known as Geppei (Trojan.Geppei), which is used by Cranefly (aka UNC3524) to deliver another form of undocumented backdoor malware known as Danfuan (Trojan.Danfuan), which grants secret access to infected systems and then spies on them.

Trojan.Geppei uses PyInstaller to convert Python scripts into executable files in the attacks. IIS logs are used to store IIS data such as web pages and apps. The attackers then send commands disguised as web access requests to a compromised web server.

For malicious HTTP requests parsed by Geppei, Cranefly also uses the strings Wrde, Exco, and CIIo to cause the dropper to run on a compromised Microsoft machine. Since IIS logs 404 errors by default, the attacker can inject commands into IIS log files by using dummy URLs or non-existent URLs. The “Wrde” string causes a decryption algorithm to be applied to the request:

When the Geppei malware parses an “Exco” string from an IIS log file, it decrypts the string passed as a parameter: GET [dummy string] Exco [passed string to exco()] Exco [dummy string] Using the os.system() function, the string would be executed as a command.

The last string that triggers Geppei malware is “Cllo,” which invokes a clear() function that drops a hacker tool called sckspy.exe. This tool disables the Service Control Manager’s eventlog logging. In addition, the function attempts to remove lines in the IIS log file that contain commands or malicious.ashx file paths.

The sources for this piece include an article in ZDNet.

Top Stories

Related Articles

June 9, 2026 Hackers exploited Meta’s AI-powered support chatbot to gain control of Instagram accounts, including several high-profile profiles. Meta more...

June 5, 2026 Security researchers have disclosed a new denial-of-service attack called HTTP/2 Bomb that can overwhelm major web servers more...

May 20, 2026 The Cybersecurity and Infrastructure Security Agency, the arm of the U.S. government tasked with protecting critical infrastructure more...

May 11, 2026 Instructure has restored access to its Canvas learning platform after a cyberattack disrupted service for universities and more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn