ATT&CKReferencesSentinelLabs Metador Sept 2022

SentinelLabs Metador Sept 2022

Ehrlich, A., et al. (2022, September). THE MYSTERY OF METADOR | AN UNATTRIBUTED THREAT HIDING IN TELCOS, ISPS, AND UNIVERSITIES. Retrieved January 23, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples48

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwaremetaMain

metaMain can collect files and system information from a compromised host.

T1005
Data from Local System
MalwareMafalda

Mafalda can collect files and information from a compromised host.

T1016
System Network Configuration Discovery
MalwareMafalda

Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table.

T1027.013
Encrypted/Encoded File
MalwareMafalda

Mafalda has been obfuscated and contains encrypted functions.

T1027.013
Encrypted/Encoded File
GroupMetador

Metador has encrypted their payloads.

T1041
Exfiltration Over C2 Channel
MalwareMafalda

Mafalda can send network system data and files to its C2 server.

T1049
System Network Connections Discovery
MalwareMafalda

Mafalda can use the GetExtendedTcpTable function to retrieve information about established TCP connections.

T1055
Process Injection
MalwaremetaMain

metaMain can inject the loader file, Speech02.db, into a process.

T1056.001
Keylogging
MalwaremetaMain

metaMain has the ability to log keyboard events.

T1057
Process Discovery
MalwareMafalda

Mafalda can enumerate running processes on a machine.

T1057
Process Discovery
MalwaremetaMain

metaMain can enumerate the processes that run on the platform.

T1059.003
Windows Command Shell
GroupMetador

Metador has used the Windows command line to execute commands.

T1070.004
File Deletion
MalwaremetaMain

metaMain has deleted collected items after uploading the content to its C2 server.

T1070.004
File Deletion
GroupMetador

Metador has quickly deleted `cbd.exe` from a compromised host following the successful deployment of their malware.

T1071.001
Web Protocols
MalwaremetaMain

metaMain can use HTTP for C2 communications.

T1071.001
Web Protocols
MalwareMafalda

Mafalda can use HTTP for C2.

T1071.001
Web Protocols
GroupMetador

Metador has used HTTP for C2.

T1074.001
Local Data Staging
MalwareMafalda

Mafalda can place retrieved files into a destination directory.

T1074.001
Local Data Staging
MalwaremetaMain

metaMain has stored the collected system files in a working directory.

T1082
System Information Discovery
MalwareMafalda

Mafalda can collect the computer name of a compromised host.

T1083
File and Directory Discovery
MalwareMafalda

Mafalda can search for files and directories.

T1083
File and Directory Discovery
MalwaremetaMain

metaMain can recursively enumerate files in an operator-provided directory.

T1095
Non-Application Layer Protocol
GroupMetador

Metador has used TCP for C2.

T1095
Non-Application Layer Protocol
MalwaremetaMain

metaMain can establish an indirect and raw TCP socket-based connection to the C2 server.

T1095
Non-Application Layer Protocol
MalwareMafalda

Mafalda can use raw TCP for C2.

T1105
Ingress Tool Transfer
GroupMetador

Metador has downloaded tools and malware onto a compromised system.

T1105
Ingress Tool Transfer
MalwaremetaMain

metaMain can download files onto compromised systems.

T1106
Native API
MalwaremetaMain

metaMain can execute an operator-provided Windows command by leveraging functions such as `WinExec`, `WriteFile`, and `ReadFile`.

T1106
Native API
MalwareMafalda

Mafalda can use a variety of API calls.

T1113
Screen Capture
MalwareMafalda

Mafalda can take a screenshot of the target machine and save it to a file.

T1113
Screen Capture
MalwaremetaMain

metaMain can take and save screenshots.

T1140
Deobfuscate/Decode Files or Information
MalwaremetaMain

metaMain can decrypt and load other modules.

T1140
Deobfuscate/Decode Files or Information
MalwareMafalda

Mafalda can decrypt files and data.

T1205.001
Port Knocking
MalwareMafalda

Mafalda can use port-knocking to authenticate itself to another implant called Cryshell to establish an indirect connection to the C2 server.

T1205.001
Port Knocking
MalwaremetaMain

metaMain has authenticated itself to a different implant, Cryshell, through a port knocking and handshake procedure.

T1217
Browser Information Discovery
MalwareMafalda

Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file.

T1518.001
Security Software Discovery
MalwareMafalda

Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools.

T1546.003
Windows Management Instrumentation Event Subscription
GroupMetador

Metador has established persistence through the use of a WMI event subscription combined with unusual living-off-the-land binaries such as `cdb.exe`.

T1546.003
Windows Management Instrumentation Event Subscription
MalwaremetaMain

metaMain registered a WMI event subscription consumer called "hard_disk_stat" to establish persistence.

T1552.004
Private Keys
MalwareMafalda

Mafalda can collect a Chrome encryption key used to protect browser cookies.

T1560.003
Archive via Custom Method
MalwaremetaMain

metaMain has used XOR-based encryption for collected files before exfiltration.

T1573.001
Symmetric Cryptography
MalwareMafalda

Mafalda can encrypt its C2 traffic with RC4.

T1573.001
Symmetric Cryptography
MalwaremetaMain

metaMain can encrypt the data that it sends and receives from the C2 server using an RC4 encryption algorithm.

T1588.001
Malware
GroupMetador

Metador has used unique malware in their operations, including metaMain and Mafalda.

T1588.002
Tool
GroupMetador

Metador has used Microsoft's Console Debugger in some of their operations.

T1620
Reflective Code Loading
MalwaremetaMain

metaMain has reflectively loaded a DLL to read, decrypt, and load an orchestrator file.

T1680
Local Storage Discovery
MalwareMafalda

Mafalda can enumerate all drives on a compromised host.

T1685.005
Clear Windows Event Logs
MalwareMafalda

Mafalda can delete Windows Event logs by invoking the `OpenEventLogW` and `ClearEventLogW` functions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.