AhnLab identified a backdoor named MoiClient distributed via invoice-themed phishing emails containing .VHDX files. MoiClient uses DLL side-loading via a legitimate SumatraPDF binary, RPC-based UAC bypass through the AppInfo service, and BYOVD exploiting a vulnerable Lenovo PC Manager driver (BootRepair.Sys v2.5.30.11281) to terminate security products. It maintains persistence through Task Scheduler jobs running every 30 minutes and ultimately deploys MoiXD Stealer to harvest browser credentials.
MoiClient
1 post
“Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearing