Operation LOWKEY

The APT41 threat actor used malware known as LOWKEY to target specific entities. The passive backdoor can perform a range of commands including stopping processes, downloading and uploading files, and creating a reverse shell. The malicious software listens on port 53 or port 80 to be activated and uses multiple named pipes for communication.
