Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwaremetaMain | metaMain can collect files and system information from a compromised host. |
| T1005 Data from Local System |
MalwareMafalda | Mafalda can collect files and information from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareMafalda | Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table. |
| T1027.013 Encrypted/Encoded File |
MalwareMafalda | Mafalda has been obfuscated and contains encrypted functions. |
| T1027.013 Encrypted/Encoded File |
GroupMetador | Metador has encrypted their payloads. |
| T1041 Exfiltration Over C2 Channel |
MalwareMafalda | Mafalda can send network system data and files to its C2 server. |
| T1049 System Network Connections Discovery |
MalwareMafalda | Mafalda can use the |
| T1055 Process Injection |
MalwaremetaMain | metaMain can inject the loader file, Speech02.db, into a process. |
| T1056.001 Keylogging |
MalwaremetaMain | metaMain has the ability to log keyboard events. |
| T1057 Process Discovery |
MalwareMafalda | Mafalda can enumerate running processes on a machine. |
| T1057 Process Discovery |
MalwaremetaMain | metaMain can enumerate the processes that run on the platform. |
| T1059.003 Windows Command Shell |
GroupMetador | Metador has used the Windows command line to execute commands. |
| T1070.004 File Deletion |
MalwaremetaMain | metaMain has deleted collected items after uploading the content to its C2 server. |
| T1070.004 File Deletion |
GroupMetador | Metador has quickly deleted `cbd.exe` from a compromised host following the successful deployment of their malware. |
| T1071.001 Web Protocols |
MalwaremetaMain | metaMain can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareMafalda | Mafalda can use HTTP for C2. |
| T1071.001 Web Protocols |
GroupMetador | Metador has used HTTP for C2. |
| T1074.001 Local Data Staging |
MalwareMafalda | Mafalda can place retrieved files into a destination directory. |
| T1074.001 Local Data Staging |
MalwaremetaMain | metaMain has stored the collected system files in a working directory. |
| T1082 System Information Discovery |
MalwareMafalda | Mafalda can collect the computer name of a compromised host. |
| T1083 File and Directory Discovery |
MalwareMafalda | Mafalda can search for files and directories. |
| T1083 File and Directory Discovery |
MalwaremetaMain | metaMain can recursively enumerate files in an operator-provided directory. |
| T1095 Non-Application Layer Protocol |
GroupMetador | Metador has used TCP for C2. |
| T1095 Non-Application Layer Protocol |
MalwaremetaMain | metaMain can establish an indirect and raw TCP socket-based connection to the C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareMafalda | Mafalda can use raw TCP for C2. |
| T1105 Ingress Tool Transfer |
GroupMetador | Metador has downloaded tools and malware onto a compromised system. |
| T1105 Ingress Tool Transfer |
MalwaremetaMain | metaMain can download files onto compromised systems. |
| T1106 Native API |
MalwaremetaMain | metaMain can execute an operator-provided Windows command by leveraging functions such as `WinExec`, `WriteFile`, and `ReadFile`. |
| T1106 Native API |
MalwareMafalda | Mafalda can use a variety of API calls. |
| T1113 Screen Capture |
MalwareMafalda | Mafalda can take a screenshot of the target machine and save it to a file. |
| T1113 Screen Capture |
MalwaremetaMain | metaMain can take and save screenshots. |
| T1140 Deobfuscate/Decode Files or Information |
MalwaremetaMain | metaMain can decrypt and load other modules. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMafalda | Mafalda can decrypt files and data. |
| T1205.001 Port Knocking |
MalwareMafalda | Mafalda can use port-knocking to authenticate itself to another implant called Cryshell to establish an indirect connection to the C2 server. |
| T1205.001 Port Knocking |
MalwaremetaMain | metaMain has authenticated itself to a different implant, Cryshell, through a port knocking and handshake procedure. |
| T1217 Browser Information Discovery |
MalwareMafalda | Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file. |
| T1518.001 Security Software Discovery |
MalwareMafalda | Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupMetador | Metador has established persistence through the use of a WMI event subscription combined with unusual living-off-the-land binaries such as `cdb.exe`. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwaremetaMain | metaMain registered a WMI event subscription consumer called "hard_disk_stat" to establish persistence. |
| T1552.004 Private Keys |
MalwareMafalda | Mafalda can collect a Chrome encryption key used to protect browser cookies. |
| T1560.003 Archive via Custom Method |
MalwaremetaMain | metaMain has used XOR-based encryption for collected files before exfiltration. |
| T1573.001 Symmetric Cryptography |
MalwareMafalda | Mafalda can encrypt its C2 traffic with RC4. |
| T1573.001 Symmetric Cryptography |
MalwaremetaMain | metaMain can encrypt the data that it sends and receives from the C2 server using an RC4 encryption algorithm. |
| T1588.001 Malware |
GroupMetador | Metador has used unique malware in their operations, including metaMain and Mafalda. |
| T1588.002 Tool |
GroupMetador | Metador has used Microsoft's Console Debugger in some of their operations. |
| T1620 Reflective Code Loading |
MalwaremetaMain | metaMain has reflectively loaded a DLL to read, decrypt, and load an orchestrator file. |
| T1680 Local Storage Discovery |
MalwareMafalda | Mafalda can enumerate all drives on a compromised host. |
| T1685.005 Clear Windows Event Logs |
MalwareMafalda | Mafalda can delete Windows Event logs by invoking the `OpenEventLogW` and `ClearEventLogW` functions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.