Faou, M. (2020, May). From Agent.btz to ComRAT v4: A ten-year journey. Retrieved June 15, 2020.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareComRAT | ComRAT can check the default browser by querying |
| T1016 System Network Configuration Discovery |
GroupTurla | Turla surveys a system upon check-in to discover network configuration details using the |
| T1016.001 Internet Connection Discovery |
GroupTurla | Turla has used |
| T1018 Remote System Discovery |
GroupTurla | Turla surveys a system upon check-in to discover remote systems on a local network using the |
| T1027 Obfuscated Files or Information |
MalwareComRAT | ComRAT has encrypted its virtual file system using AES-256 in XTS mode. |
| T1027.009 Embedded Payloads |
MalwareComRAT | ComRAT has embedded a XOR encrypted communications module inside the orchestrator module. |
| T1027.010 Command Obfuscation |
MalwareComRAT | ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts. |
| T1027.011 Fileless Storage |
MalwareComRAT | ComRAT has stored encrypted orchestrator code and payloads in the Registry. |
| T1029 Scheduled Transfer |
MalwareComRAT | ComRAT has been programmed to sleep outside local business hours (9 to 5, Monday to Friday). |
| T1036.004 Masquerade Task or Service |
MalwareComRAT | ComRAT has used a task name associated with Windows SQM Consolidator. |
| T1049 System Network Connections Discovery |
GroupTurla | Turla surveys a system upon check-in to discover active local network connections using the |
| T1053.005 Scheduled Task |
MalwareComRAT | ComRAT has used a scheduled task to launch its PowerShell loader. |
| T1055.001 Dynamic-link Library Injection |
MalwareComRAT | ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process. |
| T1059.001 PowerShell |
MalwareComRAT | ComRAT has used PowerShell to load itself every time a user logs in to the system. ComRAT can execute PowerShell scripts loaded into memory or from the file system. |
| T1059.003 Windows Command Shell |
MalwareComRAT | ComRAT has used |
| T1069.001 Local Groups |
GroupTurla | Turla has used |
| T1069.002 Domain Groups |
GroupTurla | Turla has used |
| T1071.001 Web Protocols |
MalwareComRAT | ComRAT has used HTTP requests for command and control. |
| T1071.003 Mail Protocols |
MalwareComRAT | ComRAT can use email attachments for command and control. |
| T1082 System Information Discovery |
GroupTurla | Turla surveys a system upon check-in to discover operating system configuration details using the |
| T1083 File and Directory Discovery |
GroupTurla | Turla surveys a system upon check-in to discover files in specific locations on the hard disk %TEMP% directory, the current user's desktop, the Program Files directory, and Recent. Turla RPC backdoors have also searched for files matching the |
| T1087.001 Local Account |
GroupTurla | Turla has used |
| T1087.002 Domain Account |
GroupTurla | Turla has used |
| T1102.002 Bidirectional Communication |
MalwareComRAT | ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. |
| T1106 Native API |
MalwareComRAT | ComRAT can load a PE file from memory or the file system and execute it with |
| T1112 Modify Registry |
MalwareComRAT | ComRAT has modified Registry values to store encrypted orchestrator code and payloads. |
| T1120 Peripheral Device Discovery |
GroupTurla | Turla has used |
| T1140 Deobfuscate/Decode Files or Information |
MalwareComRAT | ComRAT has used unique per machine passwords to decrypt the orchestrator payload and a hardcoded XOR key to decrypt its communications module. ComRAT has also used a unique password to decrypt the file used for its hidden file system. |
| T1189 Drive-by Compromise |
GroupTurla | Turla has infected victims using watering holes. |
| T1201 Password Policy Discovery |
GroupTurla | Turla has used |
| T1213.006 Databases |
GroupTurla | Turla has used a custom .NET tool to collect documents from an organization's internal central database. |
| T1518 Software Discovery |
MalwareComRAT | ComRAT can check the victim's default browser to determine which process to inject its communications module into. |
| T1518.001 Security Software Discovery |
GroupTurla | Turla has obtained information on security software, including security logging information that may indicate whether their malware has been detected. |
| T1564.005 Hidden File System |
MalwareComRAT | ComRAT has used a portable FAT16 partition image placed in %TEMP% as a hidden file system. |
| T1567.002 Exfiltration to Cloud Storage |
GroupTurla | Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared. |
| T1573.002 Asymmetric Cryptography |
MalwareComRAT | ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel. |
| T1615 Group Policy Discovery |
GroupTurla | Turla surveys a system upon check-in to discover Group Policy details using the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.