Netsh Helper DLL

Unhook EDR hooks in ntdll.dll on the target system then ingress an agent configuration file and agent DLL. Store a custom key in the registry then install a Netsh helper DLL. The helper DLL uses SysWhispers to perform direct system calls to NtCreateThreadEx against the stored registry key entry.
Authors:khyberspache, nicholas spagnola (@makosec), mantvydas baranauskas (@spotheplanet), oddvar moe @oddvarmoe, freddie barr-smith, riccardo spolaor, mariano graziano, xabier ugarte-pedrero

Execute this chain

Download Operator (1.7.1)
Learn about Operator

TTPs

Unhook ntdll.dll EDR hooks via remapping
Create specific registry key in HKLM
Stage agent configuration file
Ingress Pneuma DLL with exported LaunchPneuma function
Netsh helper dll persistence

Tags

kaseya vsa attack