High Impact Factor : 4.396 icon | Submit Manuscript Online icon |

A Study of Cosmicstrand Malware Mechanism

Author(s):

Chinmay Pandey , Ajeenkya D.Y. Patil University; Sukhesh Kothari, Ajeenkya D.Y. Patil University

Keywords:

CosmicStrand, Malware Mechanism, MITRE ATTACK

Abstract

A rootkit is a malware that hides in and operates from parts of the operating system that are inaccessible by traditional anti-malware solutions as this part is directly involved with booting stage of operating system itself. Though they appear as a lucrative option to any adversary in theory, creating one requires the developer to pass through several technological obstacles. Small programming error has the potential to break system and may lead to entirely crash the target. In APT predictions for 2022, done by Securelist, it was mentioned that they expected increase in number of threat actors or adversaries to acquire the complexity and sophistication level required to develop such tools [1]. A primary feature of malware that works in these low levels of any system is that it is extremely portable, stealthy and they exploit inherent design flaws within that level of system. The level of operation and its impacted stealth ensures for rootkit that the malware will still persist even if the owner reinstalls the entire operating system. Rootkit is an umbrella term and has five common types which are User-mode rootkits, Kernel mode rootkits, Boot-kits, Hypervisor level rootkits, Firmware and Hardware rootkits [2]. As per MITRE ATTACK framework, an adversary may use it to hide the presence of something specific such as a program, a file, malicious services or other system components as rootkits hide their own existence as well as the existence of malware by manipulating system’s own API calls that may supply that information [3]. Another example of UEFI malware called LoJax has been documented on MITRE which was used by APT28 threat actor as a procedure of maintaining remote access on target computers [4]. The primary aim of this review paper was to review how CosmicStrand behaves and what its mechanisms are. Its family was first discovered by Qihoo360 and this partner of Securelist published a blog about the early variant in 2017 [1,5].

Other Details

Paper ID: IJSRDV11I20165
Published in: Volume : 11, Issue : 2
Publication Date: 01/05/2023
Page(s): 236-239

Article Preview

Download Article