Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareNinja | Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests. |
| T1001.003 Protocol or Service Impersonation |
MalwareNinja | Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic. |
| T1005 Data from Local System |
MalwareSamurai | Samurai can leverage an exfiltration module to download arbitrary files from compromised machines. |
| T1012 Query Registry |
MalwareSamurai | Samurai can query `SOFTWARE\Microsoft\.NETFramework\policy\v2.0` for discovery. |
| T1016 System Network Configuration Discovery |
MalwareNinja | Ninja can enumerate the IP address on compromised systems. |
| T1027 Obfuscated Files or Information |
MalwareSamurai | Samurai can encrypt the names of requested APIs. |
| T1027.004 Compile After Delivery |
MalwareSamurai | Samurai can compile and execute downloaded modules at runtime. |
| T1027.007 Dynamic API Resolution |
MalwareSamurai | Samurai can encrypt API name strings with an XOR-based algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwareNinja | The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`. |
| T1027.015 Compression |
MalwareNinja | Ninja has compressed its data with the LZSS algorithm. |
| T1027.015 Compression |
MalwareSamurai | Samurai can deliver its final payload as a compressed, encrypted and base64-encoded blob. |
| T1029 Scheduled Transfer |
MalwareNinja | Ninja can configure its agent to work only in specific time frames. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupToddyCat | ToddyCat has used the name `debug.exe` for malware components. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSamurai | Samurai has created the directory `%COMMONPROGRAMFILES%\Microsoft Shared\wmi\` to contain DLLs for loading successive stages. |
| T1055 Process Injection |
MalwareNinja | Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes. |
| T1057 Process Discovery |
MalwareNinja | Ninja can enumerate processes on a targeted host. |
| T1059.003 Windows Command Shell |
MalwareSamurai | Samurai can use a remote command module for execution via the Windows command line. |
| T1070.006 Timestomp |
MalwareNinja | Ninja can change or create the last access or write times. |
| T1071.001 Web Protocols |
MalwareNinja | Ninja can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareSamurai | Samurai can use a .NET HTTPListener class to receive and handle HTTP POST requests. |
| T1082 System Information Discovery |
MalwareNinja | Ninja can obtain the computer name and information on the OS from targeted hosts. |
| T1083 File and Directory Discovery |
MalwareSamurai | Samurai can use a specific module for file enumeration. |
| T1083 File and Directory Discovery |
MalwareNinja | Ninja has the ability to enumerate directory content. |
| T1090 Proxy |
MalwareSamurai | Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module. |
| T1090.001 Internal Proxy |
MalwareNinja | Ninja can proxy C2 communications including to and from internal agents without internet connectivity. |
| T1090.003 Multi-hop Proxy |
MalwareNinja | Ninja has the ability to use a proxy chain with up to 255 hops when using TCP. |
| T1095 Non-Application Layer Protocol |
MalwareNinja | Ninja can forward TCP packets between the C2 and a remote host. |
| T1095 Non-Application Layer Protocol |
MalwareSamurai | Samurai can use a proxy module to forward TCP packets to external hosts. |
| T1105 Ingress Tool Transfer |
MalwareChina Chopper | China Chopper's server component can download remote files. |
| T1105 Ingress Tool Transfer |
MalwareSamurai | Samurai has been used to deploy other malware including Ninja. |
| T1106 Native API |
MalwareNinja | The Ninja loader can call Windows APIs for discovery, process injection, and payload decryption. |
| T1106 Native API |
MalwareSamurai | Samurai has the ability to call Windows APIs. |
| T1112 Modify Registry |
MalwareSamurai | The Samurai loader component can create multiple Registry keys to force the svchost.exe process to load the final backdoor. |
| T1132.001 Standard Encoding |
MalwareSamurai | Samurai can base64 encode data sent in C2 communications prior to its encryption. |
| T1132.002 Non-Standard Encoding |
MalwareNinja | Ninja can encode C2 communications with a base64 algorithm using a custom alphabet. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNinja | The Ninja loader component can decrypt and decompress the payload. |
| T1190 Exploit Public-Facing Application |
GroupToddyCat | ToddyCat has exploited the ProxyLogon vulnerability (CVE-2021-26855) to compromise Exchange Servers at multiple organizations. |
| T1204.002 Malicious File |
MalwareNinja | Ninja has gained execution through victims opening malicious executable files embedded in zip archives. |
| T1480.001 Environmental Keying |
MalwareNinja | Ninja can store its final payload in the Registry under `$HKLM\SOFTWARE\Classes\Interface\` encrypted with a dynamically generated key based on the drive’s serial number. |
| T1518 Software Discovery |
MalwareSamurai | Samurai can check for the presence and version of the .NET framework. |
| T1543.003 Windows Service |
MalwareSamurai | Samurai can create a service at `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost` to trigger execution and maintain persistence. |
| T1543.003 Windows Service |
MalwareNinja | Ninja can create the services `httpsvc` and `w3esvc` for persistence . |
| T1559 Inter-Process Communication |
MalwareNinja | Ninja can use pipes to redirect the standard input and the standard output. |
| T1566.003 Spearphishing via Service |
GroupToddyCat | ToddyCat has sent loaders configured to run Ninja as zip archives via Telegram. |
| T1566.003 Spearphishing via Service |
MalwareNinja | Ninja has been distributed to victims via the messaging app Telegram. |
| T1573.001 Symmetric Cryptography |
MalwareSamurai | Samurai can encrypt C2 communications with AES. |
| T1573.001 Symmetric Cryptography |
MalwareNinja | Ninja can XOR and AES encrypt C2 messages. |
| T1680 Local Storage Discovery |
MalwareNinja | Ninja can obtain information on physical drives from targeted hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.