ATT&CKReferencesFOX-IT May 2016 Mofang

FOX-IT May 2016 Mofang

Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples43

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareShimRat

ShimRat has the capability to upload collected files to a C2.

T1008
Fallback Channels
MalwareShimRat

ShimRat has used a secondary C2 location if the first was unavailable.

T1016
System Network Configuration Discovery
ToolShimRatReporter

ShimRatReporter gathered the local proxy, domain, IP, routing tables, mac address, gateway, DNS servers, and DHCP status information from an infected host.

T1020
Automated Exfiltration
ToolShimRatReporter

ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2.

T1027
Obfuscated Files or Information
ToolShimRatReporter

ShimRatReporter encrypted gathered information with a combination of shifting and XOR using a static key.

T1027.002
Software Packing
MalwareShimRat

ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack.

T1027.013
Encrypted/Encoded File
GroupMofang

Mofang has encrypted payloads before they are downloaded to victims.

T1027.015
Compression
GroupMofang

Mofang has compressed the ShimRat executable within malicious email attachments.

T1027.015
Compression
MalwareShimRat

ShimRat has been delivered as a package that includes compressed DLL and shellcode payloads within a .dat file.

T1029
Scheduled Transfer
MalwareShimRat

ShimRat can sleep when instructed to do so by the C2.

T1036.004
Masquerade Task or Service
MalwareShimRat

ShimRat can impersonate Windows services and antivirus products to avoid detection on compromised systems.

T1036.005
Match Legitimate Resource Name or Location
ToolShimRatReporter

ShimRatReporter spoofed itself as AlphaZawgyl_font.exe, a specialized Unicode font.

T1041
Exfiltration Over C2 Channel
ToolShimRatReporter

ShimRatReporter sent generated reports to the C2 via HTTP POST requests.

T1049
System Network Connections Discovery
ToolShimRatReporter

ShimRatReporter used the Windows function GetExtendedUdpTable to detect connected UDP endpoints.

T1057
Process Discovery
ToolShimRatReporter

ShimRatReporter listed all running processes on the machine.

T1059.003
Windows Command Shell
MalwareShimRat

ShimRat can be issued a command shell function from the C2.

T1069
Permission Groups Discovery
ToolShimRatReporter

ShimRatReporter gathered the local privileges for the infected host.

T1070.004
File Deletion
MalwareShimRat

ShimRat can uninstall itself from compromised hosts, as well create and modify directories, delete, move, copy, and rename files.

T1071.001
Web Protocols
MalwareShimRat

ShimRat communicated over HTTP and HTTPS with C2 servers.

T1071.001
Web Protocols
ToolShimRatReporter

ShimRatReporter communicated over HTTP with preconfigured C2 servers.

T1082
System Information Discovery
ToolShimRatReporter

ShimRatReporter gathered the operating system name and specific Windows version of an infected machine.

T1083
File and Directory Discovery
MalwareShimRat

ShimRat can list directories.

T1087
Account Discovery
ToolShimRatReporter

ShimRatReporter listed all non-privileged and privileged accounts available on the machine.

T1090.002
External Proxy
MalwareShimRat

ShimRat can use pre-configured HTTP proxies.

T1105
Ingress Tool Transfer
MalwareShimRat

ShimRat can download additional files.

T1105
Ingress Tool Transfer
ToolShimRatReporter

ShimRatReporter had the ability to download additional payloads.

T1106
Native API
ToolShimRatReporter

ShimRatReporter used several Windows API functions to gather information from the infected system.

T1106
Native API
MalwareShimRat

ShimRat has used Windows API functions to install the service and shim.

T1112
Modify Registry
MalwareShimRat

ShimRat has registered two registry keys for shim databases.

T1119
Automated Collection
ToolShimRatReporter

ShimRatReporter gathered information automatically, without instruction from a C2, related to the user and host machine that is compiled into a report and sent to the operators.

T1135
Network Share Discovery
MalwareShimRat

ShimRat can enumerate connected drives for infected host machines.

T1140
Deobfuscate/Decode Files or Information
MalwareShimRat

ShimRat has decompressed its core DLL using shellcode once an impersonated antivirus component was running on a system.

T1204.001
Malicious Link
GroupMofang

Mofang's spearphishing emails required a user to click the link to connect to a compromised website.

T1204.002
Malicious File
GroupMofang

Mofang's malicious spearphishing attachments required a user to open the file after receiving.

T1518
Software Discovery
ToolShimRatReporter

ShimRatReporter gathered a list of installed software on the infected host.

T1543.003
Windows Service
MalwareShimRat

ShimRat has installed a Windows service to maintain persistence on victim machines.

T1546.011
Application Shimming
MalwareShimRat

ShimRat has installed shim databases in the AppPatch folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareShimRat

ShimRat has installed a registry based start-up key HKCU\Software\microsoft\windows\CurrentVersion\Run to maintain persistence should other methods fail.

T1548.002
Bypass User Account Control
MalwareShimRat

ShimRat has hijacked the cryptbase.dll within migwiz.exe to escalate privileges. This prevented the User Access Control window from appearing.

T1560
Archive Collected Data
ToolShimRatReporter

ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2.

T1566.001
Spearphishing Attachment
GroupMofang

Mofang delivered spearphishing emails with malicious documents, PDFs, or Excel files attached.

T1566.002
Spearphishing Link
GroupMofang

Mofang delivered spearphishing emails with malicious links included.

T1574
Hijack Execution Flow
MalwareShimRat

ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.