ATT&CKReferencesKaspersky ToddyCat June 2022

Kaspersky ToddyCat June 2022

Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples48

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareNinja

Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests.

T1001.003
Protocol or Service Impersonation
MalwareNinja

Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic.

T1005
Data from Local System
MalwareSamurai

Samurai can leverage an exfiltration module to download arbitrary files from compromised machines.

T1012
Query Registry
MalwareSamurai

Samurai can query `SOFTWARE\Microsoft\.NETFramework\policy\v2.0` for discovery.

T1016
System Network Configuration Discovery
MalwareNinja

Ninja can enumerate the IP address on compromised systems.

T1027
Obfuscated Files or Information
MalwareSamurai

Samurai can encrypt the names of requested APIs.

T1027.004
Compile After Delivery
MalwareSamurai

Samurai can compile and execute downloaded modules at runtime.

T1027.007
Dynamic API Resolution
MalwareSamurai

Samurai can encrypt API name strings with an XOR-based algorithm.

T1027.013
Encrypted/Encoded File
MalwareNinja

The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`.

T1027.015
Compression
MalwareNinja

Ninja has compressed its data with the LZSS algorithm.

T1027.015
Compression
MalwareSamurai

Samurai can deliver its final payload as a compressed, encrypted and base64-encoded blob.

T1029
Scheduled Transfer
MalwareNinja

Ninja can configure its agent to work only in specific time frames.

T1036.005
Match Legitimate Resource Name or Location
GroupToddyCat

ToddyCat has used the name `debug.exe` for malware components.

T1036.005
Match Legitimate Resource Name or Location
MalwareSamurai

Samurai has created the directory `%COMMONPROGRAMFILES%\Microsoft Shared\wmi\` to contain DLLs for loading successive stages.

T1055
Process Injection
MalwareNinja

Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes.

T1057
Process Discovery
MalwareNinja

Ninja can enumerate processes on a targeted host.

T1059.003
Windows Command Shell
MalwareSamurai

Samurai can use a remote command module for execution via the Windows command line.

T1070.006
Timestomp
MalwareNinja

Ninja can change or create the last access or write times.

T1071.001
Web Protocols
MalwareNinja

Ninja can use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareSamurai

Samurai can use a .NET HTTPListener class to receive and handle HTTP POST requests.

T1082
System Information Discovery
MalwareNinja

Ninja can obtain the computer name and information on the OS from targeted hosts.

T1083
File and Directory Discovery
MalwareSamurai

Samurai can use a specific module for file enumeration.

T1083
File and Directory Discovery
MalwareNinja

Ninja has the ability to enumerate directory content.

T1090
Proxy
MalwareSamurai

Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module.

T1090.001
Internal Proxy
MalwareNinja

Ninja can proxy C2 communications including to and from internal agents without internet connectivity.

T1090.003
Multi-hop Proxy
MalwareNinja

Ninja has the ability to use a proxy chain with up to 255 hops when using TCP.

T1095
Non-Application Layer Protocol
MalwareNinja

Ninja can forward TCP packets between the C2 and a remote host.

T1095
Non-Application Layer Protocol
MalwareSamurai

Samurai can use a proxy module to forward TCP packets to external hosts.

T1105
Ingress Tool Transfer
MalwareChina Chopper

China Chopper's server component can download remote files.

T1105
Ingress Tool Transfer
MalwareSamurai

Samurai has been used to deploy other malware including Ninja.

T1106
Native API
MalwareNinja

The Ninja loader can call Windows APIs for discovery, process injection, and payload decryption.

T1106
Native API
MalwareSamurai

Samurai has the ability to call Windows APIs.

T1112
Modify Registry
MalwareSamurai

The Samurai loader component can create multiple Registry keys to force the svchost.exe process to load the final backdoor.

T1132.001
Standard Encoding
MalwareSamurai

Samurai can base64 encode data sent in C2 communications prior to its encryption.

T1132.002
Non-Standard Encoding
MalwareNinja

Ninja can encode C2 communications with a base64 algorithm using a custom alphabet.

T1140
Deobfuscate/Decode Files or Information
MalwareNinja

The Ninja loader component can decrypt and decompress the payload.

T1190
Exploit Public-Facing Application
GroupToddyCat

ToddyCat has exploited the ProxyLogon vulnerability (CVE-2021-26855) to compromise Exchange Servers at multiple organizations.

T1204.002
Malicious File
MalwareNinja

Ninja has gained execution through victims opening malicious executable files embedded in zip archives.

T1480.001
Environmental Keying
MalwareNinja

Ninja can store its final payload in the Registry under `$HKLM\SOFTWARE\Classes\Interface\` encrypted with a dynamically generated key based on the drive’s serial number.

T1518
Software Discovery
MalwareSamurai

Samurai can check for the presence and version of the .NET framework.

T1543.003
Windows Service
MalwareSamurai

Samurai can create a service at `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost` to trigger execution and maintain persistence.

T1543.003
Windows Service
MalwareNinja

Ninja can create the services `httpsvc` and `w3esvc` for persistence .

T1559
Inter-Process Communication
MalwareNinja

Ninja can use pipes to redirect the standard input and the standard output.

T1566.003
Spearphishing via Service
GroupToddyCat

ToddyCat has sent loaders configured to run Ninja as zip archives via Telegram.

T1566.003
Spearphishing via Service
MalwareNinja

Ninja has been distributed to victims via the messaging app Telegram.

T1573.001
Symmetric Cryptography
MalwareSamurai

Samurai can encrypt C2 communications with AES.

T1573.001
Symmetric Cryptography
MalwareNinja

Ninja can XOR and AES encrypt C2 messages.

T1680
Local Storage Discovery
MalwareNinja

Ninja can obtain information on physical drives from targeted hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.