Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareKGH_SPY | KGH_SPY can send a file containing victim system information to C2. |
| T1027.002 Software Packing |
ToolCSPY Downloader | CSPY Downloader has been packed with UPX. |
| T1027.013 Encrypted/Encoded File |
MalwareKGH_SPY | KGH_SPY has used encrypted strings in its installer. |
| T1036.004 Masquerade Task or Service |
ToolCSPY Downloader | CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKGH_SPY | KGH_SPY has masqueraded as a legitimate Windows tool. |
| T1037.001 Logon Script (Windows) |
MalwareKGH_SPY | KGH_SPY has the ability to set the |
| T1041 Exfiltration Over C2 Channel |
MalwareKGH_SPY | KGH_SPY can exfiltrate collected information from the host to the C2 server. |
| T1053.005 Scheduled Task |
ToolCSPY Downloader | CSPY Downloader can use the schtasks utility to bypass UAC. |
| T1056.001 Keylogging |
MalwareKGH_SPY | KGH_SPY can perform keylogging by polling the |
| T1059.001 PowerShell |
MalwareKGH_SPY | KGH_SPY can execute PowerShell commands on the victim's machine. |
| T1059.003 Windows Command Shell |
MalwareKGH_SPY | KGH_SPY has the ability to set a Registry key to run a cmd.exe command. |
| T1070 Indicator Removal |
ToolCSPY Downloader | CSPY Downloader has the ability to remove values it writes to the Registry. |
| T1070.004 File Deletion |
ToolCSPY Downloader | CSPY Downloader has the ability to self delete. |
| T1070.006 Timestomp |
GroupKimsuky | Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics. |
| T1071.001 Web Protocols |
MalwareKGH_SPY | KGH_SPY can send data to C2 with HTTP POST requests. |
| T1071.001 Web Protocols |
ToolCSPY Downloader | CSPY Downloader can use GET requests to download additional payloads from C2. |
| T1074.001 Local Data Staging |
MalwareKGH_SPY | KGH_SPY can save collected system information to a file named "info" before exfiltration. |
| T1083 File and Directory Discovery |
MalwareKGH_SPY | KGH_SPY can enumerate files and directories on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareKGH_SPY | KGH_SPY has the ability to download and execute code from remote servers. |
| T1105 Ingress Tool Transfer |
ToolCSPY Downloader | CSPY Downloader can download additional tools to a compromised host. |
| T1112 Modify Registry |
ToolCSPY Downloader | CSPY Downloader can write to the Registry under the |
| T1114.001 Local Email Collection |
MalwareKGH_SPY | KGH_SPY can harvest data from mail clients. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKGH_SPY | KGH_SPY can decrypt encrypted strings and write them to a newly created folder. |
| T1204.002 Malicious File |
MalwareKGH_SPY | KGH_SPY has been spread through Word documents containing malicious macros. |
| T1204.002 Malicious File |
ToolCSPY Downloader | CSPY Downloader has been delivered via malicious documents with embedded macros. |
| T1204.002 Malicious File |
GroupKimsuky | Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background. |
| T1497.001 System Checks |
ToolCSPY Downloader | CSPY Downloader can search loaded modules, PEB structure, file paths, Registry keys, and memory to determine if it is being debugged or running in a virtual environment. |
| T1518 Software Discovery |
MalwareKGH_SPY | KGH_SPY can collect information on installed applications. |
| T1548.002 Bypass User Account Control |
ToolCSPY Downloader | CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges. |
| T1553.002 Code Signing |
ToolCSPY Downloader | CSPY Downloader has come signed with revoked certificates. |
| T1555 Credentials from Password Stores |
MalwareKGH_SPY | KGH_SPY can collect credentials from WINSCP. |
| T1555.003 Credentials from Web Browsers |
MalwareKGH_SPY | KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers. |
| T1555.004 Windows Credential Manager |
MalwareKGH_SPY | KGH_SPY can collect credentials from the Windows Credential Manager. |
| T1566.001 Spearphishing Attachment |
GroupKimsuky | Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links. |
| T1583.001 Domains |
GroupKimsuky | Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges. |
| T1680 Local Storage Discovery |
MalwareKGH_SPY | KGH_SPY can collect drive information from a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.