InvisiMole has a modular architecture that begins working with a DLL wrapper. It then makes use of two other feature-rich backdoor modules embedded in its resources. In this way, it successfully collects the maximum possible data.
The main smaller module RC2FM includes a backdoor empowered by 15 supported commands. This module allows the attacker to search for system files. It also enables controlling the system’s camera and microphone.
The second module RC2CL is an advanced module with extensive spying capabilities including registry key manipulations, running remote shell commands, file execution, loading drivers, accessing a list of local apps, and disabling UAC. It can even act as a proxy, turning off Windows firewall, and can send data to C&C servers.
Moreover, the developers have employed a few techniques to escape detection. This way, the software remains active on the victim’s computer for longer, continuing with its malicious activities.
“The campaign is highly targeted – no wonder the malware has a low infection ratio, with only a few dozen computers being affected.”
Owing to its highly equipped design, this tool seems to outclass all other espionage tools known yet.
Though the researchers have explained quite a lot about the technicalities associated with this spyware, several things still need an answer. For instance, why the authors used two modules with overlapping functionalities is still unclear. So far, the modules appear to be adding more complexity to the malware with more research needed to uncover it further.