ATT&CKReferencesNCC Group Team9 June 2020

NCC Group Team9 June 2020

Pantazopoulos, N. (2020, June 2). In-depth analysis of the new Team9 malware family. Retrieved December 1, 2020.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples29

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareBazar

Bazar has the ability to use an alternative C2 server if the primary server fails.

T1012
Query Registry
MalwareBazar

Bazar can query Windows\CurrentVersion\Uninstall for installed applications.

T1027.007
Dynamic API Resolution
MalwareBazar

Bazar can hash then resolve API calls at runtime.

T1027.013
Encrypted/Encoded File
MalwareBazar

Bazar has used XOR, RSA2, and RC4 encrypted files.

T1033
System Owner/User Discovery
MalwareBazar

Bazar can identify the username of the infected user.

T1036.005
Match Legitimate Resource Name or Location
MalwareBazar

The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software.

T1053.005
Scheduled Task
MalwareBazar

Bazar can create a scheduled task for persistence.

T1055.012
Process Hollowing
MalwareBazar

Bazar can inject into a target process including Svchost, Explorer, and cmd using process hollowing.

T1055.013
Process Doppelgänging
MalwareBazar

Bazar can inject into a target process using process doppelgänging.

T1059.001
PowerShell
MalwareBazar

Bazar can execute a PowerShell script received from C2.

T1070.004
File Deletion
MalwareBazar

Bazar can delete its loader using a batch file in the Windows temporary folder.

T1070.009
Clear Persistence
MalwareBazar

Bazar's loader can delete scheduled tasks created by a previous instance of the malware.

T1071.001
Web Protocols
MalwareBazar

Bazar can use HTTP and HTTPS over ports 80 and 443 in C2 communications.

T1082
System Information Discovery
MalwareBazar

Bazar can fingerprint architecture, computer name, and OS version on the compromised host. Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found.

T1083
File and Directory Discovery
MalwareBazar

Bazar can enumerate the victim's desktop.

T1087.001
Local Account
MalwareBazar

Bazar can identify administrator accounts on an infected host.

T1087.002
Domain Account
MalwareBazar

Bazar has the ability to identify domain administrator accounts.

T1105
Ingress Tool Transfer
MalwareBazar

Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike.

T1124
System Time Discovery
MalwareBazar

Bazar can collect the time on the compromised host.

T1135
Network Share Discovery
MalwareBazar

Bazar can enumerate shared drives on the domain.

T1140
Deobfuscate/Decode Files or Information
MalwareBazar

Bazar can decrypt downloaded payloads. Bazar also resolves strings and other artifacts at runtime.

T1197
BITS Jobs
MalwareBazar

Bazar has been downloaded via Windows BITS functionality.

T1482
Domain Trust Discovery
MalwareBazar

Bazar can use Nltest tools to obtain information about the domain.

T1497.003
Time Based Checks
MalwareBazar

Bazar can use a timer to delay execution of core functionality.

T1547.001
Registry Run Keys / Startup Folder
MalwareBazar

Bazar can create or add files to Registry Run Keys to establish persistence.

T1547.009
Shortcut Modification
MalwareBazar

Bazar can establish persistence by writing shortcuts to the Windows Startup folder.

T1573.001
Symmetric Cryptography
MalwareBazar

Bazar can send C2 communications with XOR encryption.

T1614.001
System Language Discovery
MalwareBazar

Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian.

T1685
Disable or Modify Tools
MalwareBazar

Bazar has manually loaded ntdll from disk in order to identity and remove API hooks set by security products.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.