ATT&CKReferencesLookout Dark Caracal Jan 2018

Lookout Dark Caracal Jan 2018

Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

Open the source

Techniques1

Groups1

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupDark Caracal

Dark Caracal collected complete contents of the 'Pictures' folder from compromised Windows systems.

T1027.002
Software Packing
GroupDark Caracal

Dark Caracal has used UPX to pack Bandook.

T1027.013
Encrypted/Encoded File
GroupDark Caracal

Dark Caracal has obfuscated strings in Bandook by base64 encoding, and then encrypting them.

T1055.012
Process Hollowing
MalwareBandook

Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload.

T1059.003
Windows Command Shell
GroupDark Caracal

Dark Caracal has used macros in Word documents that would download a second stage if executed.

T1071.001
Web Protocols
GroupDark Caracal

Dark Caracal's version of Bandook communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”.

T1083
File and Directory Discovery
GroupDark Caracal

Dark Caracal collected file listings of all default Windows directories.

T1083
File and Directory Discovery
MalwareCrossRAT

CrossRAT can list all files on a system.

T1113
Screen Capture
GroupDark Caracal

Dark Caracal took screenshots using their Windows malware.

T1113
Screen Capture
MalwareBandook

Bandook is capable of taking an image of and uploading the current desktop.

T1113
Screen Capture
MalwareCrossRAT

CrossRAT is capable of taking screen captures.

T1189
Drive-by Compromise
GroupDark Caracal

Dark Caracal leveraged a watering hole to serve up malicious code.

T1204.002
Malicious File
GroupDark Caracal

Dark Caracal makes their malware look like Flash Player, Office, or PDF documents in order to entice a user to click on it.

T1218.001
Compiled HTML File
GroupDark Caracal

Dark Caracal leveraged a compiled HTML file that contained a command to download and run an executable.

T1543.001
Launch Agent
MalwareCrossRAT

CrossRAT creates a Launch Agent on macOS.

T1547.001
Registry Run Keys / Startup Folder
GroupDark Caracal

Dark Caracal's version of Bandook adds a registry key to HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareCrossRAT

CrossRAT uses run keys for persistence on Windows.

T1566.003
Spearphishing via Service
GroupDark Caracal

Dark Caracal spearphished victims via Facebook and Whatsapp.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.