PULSE NAME
A Cereal Offender: Analyzing the CORNFLAKE.V3 Backdoor
WHITE UNC5518 and UNC5774 AlienVault 2025-08-21 Modified: 2025-09-20
13
IOCs
MEDIUM VOLUME
This analysis details a campaign involving two threat groups, UNC5518 and UNC5774, deploying the CORNFLAKE.V3 backdoor. UNC5518 compromises legitimate websites to serve fake CAPTCHA pages, luring visitors to execute a downloader script. UNC5774 then uses this access to deploy CORNFLAKE.V3, a sophisticated backdoor with variants in JavaScript and PHP. The malware collects system information, establishes persistence, and can execute various payloads including shell commands, executables, and DLLs. It communicates with command and control servers using HTTP and can abuse Cloudflare Tunnels for traffic proxying. The campaign also involves active directory reconnaissance and credential harvesting attempts via Kerberoasting.
Indicators of Compromise (13)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 290cd148ed2f4995f099b7370437509b 2025-08-21
FileHash-MD5 e033f9800a5ba44b23b3026cf1c38c72 2025-08-21
FileHash-SHA1 6674d9f899d6e5762450380aa6c68ba20cf312d9 2025-08-21
FileHash-SHA256 000b24076cae8dbb00b46bb59188a0da5a940e325eaac7d86854006ec071ac5b 2025-08-21
FileHash-SHA256 14f9fbbf7e82888bdc9c314872bf0509835a464d1f03cd8e1a629d0c4d268b0c 2025-08-21
FileHash-SHA256 905373a059aecaf7f48c1ce10ffbd5334457ca00f678747f19db5ea7d256c236 2025-08-21
FileHash-SHA256 a2d4e8c3094c959e144f46b16b40ed29cc4636b88616615b69979f0a44f9a2d1 2025-08-21
URL http://dnsmicrosoftds-data.com/log/out 2025-08-21
URL http://windows-msg-as.live/qwV1jxQ 2025-08-21
domain chcp.com 2025-08-21
domain dnsmicrosoftds-data.com 2025-08-21
domain windows-msg-as.live 2025-08-21
hostname varying-rentals-calgary-predict.trycloudflare.com 2025-08-21