‘Narrator’ Windows Utility Trojanized to Gain Full System Control

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,210
A suspected Chinese advanced persistent threat (APT) group has been spotted attacking tech companies using a trojanized screen-reader application, replacing the built-in Narrator “Ease of Access” feature in Windows.

The attackers also deploy a version of the open-source malware known as the PcShare backdoor to gain an initial foothold into victims’ systems.
Using the two tools, the adversaries are able to surreptitiously control Windows machines via remote desktop logon screens, without the need for credentials.

The attacks begin by delivering the PcShare backdoor to victims via spearphishing campaigns. It has been modified and designed to operate when side-loaded by a legitimate NVIDIA application.
 

[correlate]

Level 18
Top Poster
Well-known
May 4, 2019
801
Researchers have discovered a malware campaign targeting computers throughout Asia which looks to replace Windows Narrator with a malicious version. The malicious version, in turn, grants the attacker not only remote access but almost unfettered persistence. Windows Narrator forms part of Microsoft’s Ease of Access suite which is built into Windows 10 and operates as a screen reader. Narrator is designed to improve the accessibility of machines running Windows 10 so those with low-level vision can use the machine relatively unhindered. The software also replaces the mouse to receive voice commands and is compatible with braille displays.

Researchers working for BlackBerry Cylance discovered the campaign and noticed that the campaign targets predominantly systems belonging to technology companies based in Southeast Asia. In a report published by Cylance, it was noted that the attackers use a modified and open source piece of software which grants remote access. Called PCShare by its developers it is currently available via GitHub. The tool is heavily modified and customized for the campaign at hand, featuring a tailored command-and-control (C2) servers, encryption, and proxy bypass functionality. At the same time, all code not deemed useful to the attacker’s goals is removed from the source code.

 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top