Samurai Backdoor
Summary
Initially, the ToddyCat APT was focused on compromising selected Exchange servers located in Taiwan and Vietnam. However, soon after that, they began targeting numerous organizations in both Europe and Asia by abusing the ProxyLogon vulnerability. It is responsible for installing the other threatening components and creating several Registry keys capable of forcing the legitimate svchost.exe process to load the Samurai malware. The infosec researchers note that Samurai has obfuscated with a specific algorithm, several of its functions are assigned random names, and it includes multiple loops and switch cases that cause jumps between instructions. The different modules of the threat are designed to handle specific tasks, depending on the received commands.