ReedBed

First seen
2024-10-01 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 13:14:11

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Context

ReedBed, identified as a malware proxy backdoor, is suspected to be developed by QAKBOT devs, and was deployed by the threat actor Storm-1811 in campaigns observed during late October and early November 2024. These campaigns are typically initiated with email bombing, a tactic involving mass email distribution, followed by social engineering strategies where the actor impersonates help desk personnel to gain access to victim systems. Upon execution, ReedBed ensures single-instance operation via the mutex "JhishdiI2Uhsvoc94keiojn7ns19m0do" and hooks critical system APIs (NtCreateUserProcess, RtlExitUserProcess) for defense evasion, process interference, and anti-termination. It reads its Command and Control (C2) configuration, typically from the "Software\TitanPlus" registry key, establishes a persistent SSL/TLS encrypted connection, and transmits an initial system information beacon. Subsequently, ReedBed enters its main operational loop, acting as a versatile network proxy based on C2 commands; this includes initiating outgoing TCP connections, relaying data bi-directionally, and establishing reverse SOCKS5 (with authentication) or direct TCP port mapping services via locally opened listening ports. If commanded or upon connection failure, it transitions into a restart/wait cycle guided by registry values, leveraging its hooked exit function to hinder termination before attempting to reconnect to the C2.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Reedbed_Auto (yara-rule)

Reports & references

  • news.sophos.com — Sophos Mdr Tracks Two Ransomware Campaigns Using Email Bombing Microsoft Teams Vishing (report)
  • esentire.com — Ongoing Email Bombing Campaigns Leading To Remote Access And Post Exploitation (report)
  • x.com — 1881751635598139714 (report)
  • medium.com — Qbot Is Back Connect 2D774052369F (report)
  • Trend Micro — Black Basta Cactus Ransomware Backconnect (report)
  • cyber.levelblue.com — Wp Levelblue Mdrs Guide Against Black Basta.Docx (report)
  • linkedin.com — Attackers Leveraging Microsoft Teams Defaults Quick Assist P1U5C (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Reedbed (report)
  • github.com — 2025 01 17 Iocs For Infrastructure Used By Affiliate Of Dark Scorpius.Txt (report)
  • reliaquest.com — Blink And Theyre In How Rapid Phishing Attacks Exploit Weaknesses (report)

External references