T1005 Data from Local System |
MalwareBeaverTail |
BeaverTail has exfiltrated data collected from local systems. |
T1016 System Network Configuration Discovery |
MalwareInvisibleFerret |
InvisibleFerret has collected the local IP address, and external IP. |
T1027.013 Encrypted/Encoded File |
MalwareBeaverTail |
BeaverTail has obfuscated strings of code with Base64 encoding within the JavaScript version of the malware. BeaverTail has also utilized the open-source tool JavaScript-Obfuscator to obfuscate strings and functions. |
T1027.013 Encrypted/Encoded File |
MalwareInvisibleFerret |
InvisibleFerret has utilized the XOR and Base64 encoding for each of its modules. InvisibleFerret has also obfuscated files with a combination of zlib, Base64 and reverse string order. InvisibleFerret has also utilized the XOR and Base64 encoding some of its Python scripts. |
T1033 System Owner/User Discovery |
MalwareInvisibleFerret |
InvisibleFerret has identified the user’s UUID and username through the "pay" module. |
T1036 Masquerading |
GroupContagious Interview |
Contagious Interview has delivered BeaverTail malware masquerading as legitimate software or applications. Contagious Interview has also delivered malicious payloads masquerading as legitimate software drivers. |
T1041 Exfiltration Over C2 Channel |
GroupContagious Interview |
Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers. |
T1041 Exfiltration Over C2 Channel |
MalwareBeaverTail |
BeaverTail has exfiltrated data collected from victim devices to C2 servers. |
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupContagious Interview |
Contagious Interview has exfiltrated victim information using FTP. |
T1056 Input Capture |
MalwareInvisibleFerret |
InvisibleFerret has collected mouse and keyboard events using “pyWinhook”. |
T1056.001 Keylogging |
MalwareInvisibleFerret |
InvisibleFerret has conducted keylogging using the Python project “pyWinHook” and "Pyhook". InvisibleFerret has also captured keylogging thread checks for changes in an active window and key presses. |
T1057 Process Discovery |
MalwareInvisibleFerret |
InvisibleFerret has the capability to query installed programs and running processes. InvisibleFerret has also identified running processes using the Python project “psutil”. |
T1059.006 Python |
MalwareInvisibleFerret |
InvisibleFerret is written in Python and has used Python scripts for execution. |
T1059.006 Python |
GroupContagious Interview |
Contagious Interview has used the Python-based malware such as InvisibleFerret to install and execute Python Packages and Python modules. |
T1059.007 JavaScript |
MalwareBeaverTail |
BeaverTail has executed malicious JavaScript code. BeaverTail has also been compiled with the Qt framework to execute in both Windows and macOS. |
T1071.001 Web Protocols |
MalwareInvisibleFerret |
InvisibleFerret has used HTTP for C2 communications. |
T1071.001 Web Protocols |
MalwareBeaverTail |
BeaverTail has used HTTP GET request to download malicious payloads to include InvisibleFerret and HTTP POST to exfiltrate data to C2 infrastructure. |
T1082 System Information Discovery |
MalwareInvisibleFerret |
InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname. |
T1082 System Information Discovery |
MalwareBeaverTail |
BeaverTail has been known to collect basic system information. BeaverTail has also collected data to include hostname and current timestamp prior to uploading data to the API endpoint `/uploads` on the C2 server. |
T1083 File and Directory Discovery |
GroupContagious Interview |
Contagious Interview has conducted key word searches within files and directories on a compromised hosts to identify files for exfiltration. |
T1083 File and Directory Discovery |
MalwareInvisibleFerret |
InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest. |
T1087.001 Local Account |
MalwareInvisibleFerret |
InvisibleFerret has queried the victim device using Python scripts to obtain the User and Hostname. |
T1095 Non-Application Layer Protocol |
MalwareInvisibleFerret |
InvisibleFerret has established a connection with the C2 server over TCP traffic. InvisibleFerret has also created a TCP reverse shell communicating via a socket connection over ports 1245, 80, 2245, 3001, and 5000. |
T1105 Ingress Tool Transfer |
MalwareInvisibleFerret |
InvisibleFerret has downloaded “AnyDesk.exe” into the user’s home directory from the C2 server when checks for the service fail to identify its presence in the victim environment. InvisibleFerret has also been configured to download additional payloads using a command which calls to the /bow URI. |
T1105 Ingress Tool Transfer |
MalwareBeaverTail |
BeaverTail has been used to download a malicious payload to include Python based malware InvisibleFerret. |
T1115 Clipboard Data |
MalwareInvisibleFerret |
InvisibleFerret has stolen data from the clipboard using the Python project “pyperclip”. InvisibleFerret has also captured clipboard contents during copy and paste operations. |
T1195.001 Compromise Software Dependencies and Development Tools |
MalwareBeaverTail |
BeaverTail has been hosted on code repositories and disseminated to victims through NPM packages. |
T1204.005 Malicious Library |
GroupContagious Interview |
Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data. |
T1217 Browser Information Discovery |
MalwareBeaverTail |
BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. |
T1219 Remote Access Tools |
MalwareInvisibleFerret |
InvisibleFerret has utilized remote access software including AnyDesk client through the “adc” module. InvisibleFerret has also downloaded the AnyDesk client should it not already exist on the compromised host by searching for `C:/Program Files(x86)/AnyDesk/AnyDesk.exe`. |
T1219.002 Remote Desktop Software |
GroupContagious Interview |
Contagious Interview has downloaded remote management and monitoring software such as “AnyDesk” for post compromise activities. |
T1489 Service Stop |
MalwareInvisibleFerret |
InvisibleFerret has terminated Chrome and Brave browsers using the `taskkill` command on Windows and the `killall` command on other systems such as Linux and macOS. InvisibleFerret has also utilized it’s `ssh_kill` command to terminate Chrome and Brave browser processes. |
T1571 Non-Standard Port |
MalwareBeaverTail |
BeaverTail has communicated with C2 IP addresses over ports 1224 or 1244. |
T1583.003 Virtual Private Server |
GroupContagious Interview |
Contagious Interview has acquired virtual private servers from services such as Stark Industries Solutions and RouterHosting. Contagious Interview has also utilized hosting providers to include Tier[.]Net, Majestic Hosting, Leaseweb Singapore, and Kaopu Cloud. |
T1587 Develop Capabilities |
GroupContagious Interview |
Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims. |
T1588.002 Tool |
GroupContagious Interview |
Contagious Interview has used remote management and monitoring software such as “AnyDesk”. |
T1589 Gather Victim Identity Information |
GroupContagious Interview |
Contagious Interview has researched specific professional groups such as software developers for targeting. Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies. |
T1593.001 Social Media |
GroupContagious Interview |
Contagious Interview had identified and solicited victims through social media such as LinkedIn, X, and Telegram. |
T1593.003 Code Repositories |
GroupContagious Interview |
Contagious Interview had identified and solicited victims through code repositories such as GitHub. |
T1608.001 Upload Malware |
GroupContagious Interview |
Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download. |
T1614 System Location Discovery |
MalwareInvisibleFerret |
InvisibleFerret has collected the internal IP address, IP geolocation information of the infected host and sends the data to a C2 server. InvisibleFerret has also leveraged the “pay” module to obtain region name, country, city, zip code, ISP, latitude and longitude using “http://ip-api.com/json”. |
T1657 Financial Theft |
GroupContagious Interview |
Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware. |
T1657 Financial Theft |
MalwareInvisibleFerret |
InvisibleFerret has searched the victim device credentials and files commonly associated with cryptocurrency wallets. |
T1657 Financial Theft |
MalwareBeaverTail |
BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets. |
T1679 Selective Exclusion |
MalwareInvisibleFerret |
InvisibleFerret has the capability to scan for file names, file extensions, and avoids pre-designated path names and file types. |
T1684.001 Impersonation |
GroupContagious Interview |
Contagious Interview had impersonated HR hiring personnel through social media, job board notifications, and conducted interviews with victims in order to entice them to download malware disguised as legitimate applications or malicious scripts from code repositories. |