Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupToddyCat | ToddyCat has run scripts to collect documents from targeted hosts. |
| T1005 Data from Local System |
MalwareLoFiSe | LoFiSe can collect files of interest from targeted systems. |
| T1005 Data from Local System |
MalwarePcexter | Pcexter can upload files from targeted systems. |
| T1018 Remote System Discovery |
GroupToddyCat | ToddyCat has used `ping %REMOTE_HOST%` for post exploit discovery. |
| T1021.002 SMB/Windows Admin Shares |
GroupToddyCat | ToddyCat has used locally mounted network shares for lateral movement through targated environments. |
| T1027.013 Encrypted/Encoded File |
MalwareNinja | The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`. |
| T1027.015 Compression |
MalwareNinja | Ninja has compressed its data with the LZSS algorithm. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNinja | Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll. |
| T1047 Windows Management Instrumentation |
GroupToddyCat | ToddyCat has used WMI to execute scripts for post exploit document collection. |
| T1049 System Network Connections Discovery |
GroupToddyCat | ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts. |
| T1053.005 Scheduled Task |
GroupToddyCat | ToddyCat has used scheduled tasks to execute discovery commands and scripts for collection. |
| T1055 Process Injection |
MalwareNinja | Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes. |
| T1057 Process Discovery |
GroupToddyCat | ToddyCat has run `cmd /c start /b tasklist` to enumerate processes. |
| T1057 Process Discovery |
MalwareNinja | Ninja can enumerate processes on a targeted host. |
| T1059.001 PowerShell |
GroupToddyCat | ToddyCat has used Powershell scripts to perform post exploit collection. |
| T1059.003 Windows Command Shell |
GroupToddyCat | ToddyCat has used .bat scripts and `cmd` for execution on compromised hosts. |
| T1069.002 Domain Groups |
GroupToddyCat | ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines. |
| T1071.001 Web Protocols |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports. |
| T1074.001 Local Data Staging |
MalwareLoFiSe | LoFiSe can save files to be evaluated for further exfiltration in the `C:\Programdata\Microsoft\` and `C:\windows\temp\` folders. |
| T1074.002 Remote Data Staging |
GroupToddyCat | ToddyCat manually transferred collected files to an exfiltration host using xcopy. |
| T1078.002 Domain Accounts |
GroupToddyCat | ToddyCat has used compromised domain admin credentials to mount local network shares. |
| T1082 System Information Discovery |
MalwareNinja | Ninja can obtain the computer name and information on the OS from targeted hosts. |
| T1083 File and Directory Discovery |
MalwarePcexter | Pcexter has the ability to search for files in specified directories. |
| T1083 File and Directory Discovery |
MalwareLoFiSe | LoFiSe can monitor the file system to identify files less than 6.4 MB in size with file extensions including .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .tif, .odt, .ods, .odp, .eml, and .msg. |
| T1083 File and Directory Discovery |
MalwareNinja | Ninja has the ability to enumerate directory content. |
| T1083 File and Directory Discovery |
GroupToddyCat | ToddyCat has run scripts to enumerate recently modified documents having either a .pdf, .doc, .docx, .xls or .xlsx extension. |
| T1087.002 Domain Account |
GroupToddyCat | ToddyCat has run `net user %USER% /dom` for account discovery. |
| T1090.001 Internal Proxy |
MalwareNinja | Ninja can proxy C2 communications including to and from internal agents without internet connectivity. |
| T1095 Non-Application Layer Protocol |
MalwareNinja | Ninja can forward TCP packets between the C2 and a remote host. |
| T1095 Non-Application Layer Protocol |
GroupToddyCat | ToddyCat has used a passive backdoor that receives commands with UDP packets. |
| T1106 Native API |
MalwareNinja | The Ninja loader can call Windows APIs for discovery, process injection, and payload decryption. |
| T1106 Native API |
GroupToddyCat | ToddyCat has used `WinExec` to execute commands received from C2 on compromised hosts. |
| T1119 Automated Collection |
MalwareLoFiSe | LoFiSe can collect all the files from the working directory every three hours and place them into a password-protected archive for further exfiltration. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNinja | The Ninja loader component can decrypt and decompress the payload. |
| T1218.011 Rundll32 |
MalwareNinja | Ninja loader components can be executed through rundll32.exe. |
| T1518.001 Security Software Discovery |
GroupToddyCat | ToddyCat can determine is Kaspersky software is running on an endpoint by running `cmd /c wmic process where name="avp.exe"`. |
| T1560 Archive Collected Data |
MalwareLoFiSe | LoFiSe can collect files into password-protected ZIP-archives for exfiltration. |
| T1560.001 Archive via Utility |
GroupToddyCat | ToddyCat has leveraged xcopy, 7zip, and RAR to stage and compress collected documents prior to exfiltration. |
| T1564.003 Hidden Window |
GroupToddyCat | ToddyCat has hidden malicious scripts using `powershell.exe -windowstyle hidden`. |
| T1567.002 Exfiltration to Cloud Storage |
MalwarePcexter | Pcexter can upload stolen files to OneDrive storage accounts via HTTP `POST`. |
| T1567.002 Exfiltration to Cloud Storage |
GroupToddyCat | ToddyCat has used a DropBox uploader to exfiltrate stolen files. |
| T1574.001 DLL |
MalwareLoFiSe | LoFiSe has been executed as a file named DsNcDiag.dll through side-loading. |
| T1574.001 DLL |
MalwareNinja | Ninja loaders can be side-loaded with legitimate and signed executables including the VLC.exe media player. |
| T1574.001 DLL |
MalwarePcexter | Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading. |
| T1680 Local Storage Discovery |
MalwareNinja | Ninja can obtain information on physical drives from targeted hosts. |
| T1680 Local Storage Discovery |
GroupToddyCat | ToddyCat has collected information on bootable drives including model, vendor, and serial numbers. |
| T1686 Disable or Modify System Firewall |
GroupToddyCat | Prior to executing a backdoor ToddyCat has run `cmd /c start /b netsh advfirewall firewall add rule name="SGAccessInboundRule" dir=in protocol=udp action=allow localport=49683` to allow the targeted system to receive UDP packets on port 49683. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.