Analysis of Drun Backdoor and Chromelevator Loader
Score: 9/10

Analysis of Drun Backdoor and Chromelevator Loader

The Drun Backdoor is a modular two-stage infostealer that utilizes the Chromelevator loader to inject into processes via direct syscalls, targeting browser credentials, session tokens, and gaming accounts.

Executive Summary

The Drun Backdoor, often deployed via a loader referred to as 'Chromelevator', is a sophisticated two-stage information stealer first analyzed in detail in mid-2024. The threat is characterized by its high degree of evasion, employing direct system calls to bypass User Mode API hooking and integrating custom logic to circumvent Google Chrome's 'App-Bound Encryption' (introduced in version 127). The malware's modular design allows it to harvest a wide array of sensitive data including browser credentials, Discord tokens, Telegram sessions, Steam authentication files, and webcam captures.

Technical analysis reveals a complex attack chain where the 'Chromelevator' loader (drun.exe) performs architecture validation and reflective injection of an encrypted payload (payload.dll). The stealer component leverages an embedded SQLite engine to query browser databases directly, avoiding dependencies on external libraries. Exfiltration is primarily handled through Discord webhooks, with Gofile.io acting as a fallback for larger data archives. This malware represents a significant threat to personal and corporate data due to its ability to hijack authenticated sessions (Telegram, Steam, Roblox) and bypass modern browser security controls.

The urgency of this threat is high for organizations with diverse software environments, as it specifically targets various browsers (Chrome, Edge, Opera, Brave, Firefox) and communication platforms. The use of direct syscalls and encrypted payloads indicates a developer familiar with bypassing EDR and sandbox environments, necessitating robust behavioral detection strategies beyond simple IOC matching.

Key Details

Threat Name

Drun Backdoor

Affects

—

Adversary

—

Malware/Tools

Drun, chromelevator, Pay2Key, TrymeLocker, Vile, Jigsaw

Report Score

9out of 10
Quality Score
Excellent
IOC Quality6
TTP Details9
Detection Guidance9
Enterprise Relevance8
Clarity & Structure8
Technical Depth10

Sources