T1027.013 Encrypted/Encoded File |
MalwareInvisibleFerret |
InvisibleFerret has utilized the XOR and Base64 encoding for each of its modules. InvisibleFerret has also obfuscated files with a combination of zlib, Base64 and reverse string order. InvisibleFerret has also utilized the XOR and Base64 encoding some of its Python scripts. |
T1027.013 Encrypted/Encoded File |
MalwareBeaverTail |
BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions. |
T1033 System Owner/User Discovery |
MalwareInvisibleFerret |
InvisibleFerret has identified the user’s UUID and username through the "pay" module. |
T1036 Masquerading |
GroupContagious Interview |
Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers. |
T1041 Exfiltration Over C2 Channel |
GroupContagious Interview |
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. |
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareInvisibleFerret |
InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637. |
T1056.001 Keylogging |
MalwareInvisibleFerret |
InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses. |
T1059.006 Python |
GroupContagious Interview |
Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules. |
T1059.006 Python |
MalwareInvisibleFerret |
InvisibleFerret is written in Python and has used Python scripts for execution. |
T1059.007 JavaScript |
MalwareBeaverTail |
BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS. |
T1071.001 Web Protocols |
MalwareInvisibleFerret |
InvisibleFerret has used HTTP for C2 communications. |
T1082 System Information Discovery |
MalwareInvisibleFerret |
InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname. |
T1082 System Information Discovery |
MalwareBeaverTail |
BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server. |
T1083 File and Directory Discovery |
MalwareInvisibleFerret |
InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest. |
T1105 Ingress Tool Transfer |
MalwareBeaverTail |
BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret. |
T1115 Clipboard Data |
MalwareInvisibleFerret |
InvisibleFerret has stolen data from the clipboard using the Python project “pyperclip”. InvisibleFerret has also captured clipboard contents during copy and paste operations. |
T1195.001 Compromise Software Dependencies and Development Tools |
MalwareBeaverTail |
BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages. |
T1204.002 Malicious File |
MalwareBeaverTail |
BeaverTail has been executed through lures involving malicious JavaScript projects or trojanized remote conferencing software such as MicroTalk or FreeConference. BeaverTail has also been executed through macOS and Windows installers disguised as chat applications. |
T1204.005 Malicious Library |
GroupContagious Interview |
Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data. |
T1217 Browser Information Discovery |
MalwareBeaverTail |
BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. |
T1219 Remote Access Tools |
MalwareInvisibleFerret |
InvisibleFerret has utilized remote access software including AnyDesk client through the “adc” module. InvisibleFerret has also downloaded the AnyDesk client should it not already exist on the compromised host by searching for `C:/Program Files(x86)/AnyDesk/AnyDesk.exe`. |
T1219.002 Remote Desktop Software |
GroupContagious Interview |
Contagious Interview has downloaded remote management and monitoring software such as “AnyDesk” for post compromise activities. |
T1555.003 Credentials from Web Browsers |
MalwareBeaverTail |
BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration. |
T1555.003 Credentials from Web Browsers |
MalwareInvisibleFerret |
InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS. InvisibleFerret has also leveraged the command `ssh_zcp` to copy browser data to include extensions and cryptocurrency wallet data. |
T1571 Non-Standard Port |
MalwareInvisibleFerret |
InvisibleFerret has been observed utilizing HTTP communications to the C2 server over ports 1224, 2245 and 8637. |
T1583.003 Virtual Private Server |
GroupContagious Interview |
Contagious Interview has acquired virtual private servers from services such as Stark Industries Solutions and RouterHosting. Contagious Interview has also utilized hosting providers to include Tier[.]Net, Majestic Hosting, Leaseweb Singapore, and Kaopu Cloud. |
T1587 Develop Capabilities |
GroupContagious Interview |
Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims. |
T1588.002 Tool |
GroupContagious Interview |
Contagious Interview has used remote management and monitoring software such as “AnyDesk”. |
T1608.001 Upload Malware |
GroupContagious Interview |
Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. |
T1657 Financial Theft |
MalwareInvisibleFerret |
InvisibleFerret has searched the victim device credentials and files commonly associated with cryptocurrency wallets. |
T1657 Financial Theft |
GroupContagious Interview |
Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware. |
T1657 Financial Theft |
MalwareBeaverTail |
BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets. |
T1679 Selective Exclusion |
MalwareInvisibleFerret |
InvisibleFerret has the capability to scan for file names, file extensions, and avoids pre-designated path names and file types. |