How to Remove DOUBLEDRAG

The DOUBLEDRAG Malware was first spotted in a large-scale attack campaign, which targeted multiple industries, spread around the entire world. While the majority of the attacks were concentrated in the United States, the unknown criminals behind the operation also went after high-profile organizations in Europe, Africa, and the Middle East. There is not enough information to connect the DOUBLEDRAG campaign with one of the currently active Advanced Persistent Threat (APT) actors – the anonymous perpetrators are commonly referred to as UNC2529 by the research lab that first dissected their operation.

DOUBLEDRAG fulfills the purpose of a downloader, which is being used to deploy other malware used in the attacks – DOUBLEDROP and DOUBLEBACK. The DOUBLEDRAG is the first-stage payload to be delivered, and victims usually received it through a cleverly crafted spear-phishing email. The criminals made sure to use legitimate, public PDF and XLS files that were modified to include a malicious piece of code. They also crafted unique email templates for every victim to ensure that the recipient will easily mistake the bogus message for a legitimate one.

Once the DOUBLEDRAG-laced document is opened, it would execute the malicious script to deploy the threat. Interestingly enough, the DOUBLEDORP and DOUBLEBACK Malware operate from the system's memory, while the DOUBLEDRAG leaves a footprint on the hard drive. DOUBLEDRAG's purpose is to deploy the DOUBLEDROP Dropper, which would then proceed to conceal and run the DOUBLEBACK Backdoor.

This peak activity of this campaign was registered in mid-December 2020, but it is very likely that the criminals behind it are working on their next large-scale attack – so far, there is no indicator for what their end goals could be, but it is likely that UNC2529 specialize in espionage and data theft.

May 5, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.