ATT&CKReferencesUnit 42 Nokki Oct 2018

Unit 42 Nokki Oct 2018

Grunzweig, J. (2018, October 01). NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT. Retrieved November 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareFinal1stspy

Final1stspy obfuscates strings with base64 encoding.

T1027.013
Encrypted/Encoded File
MalwareDOGCALL

DOGCALL is encrypted using single-byte XOR.

T1056.001
Keylogging
MalwareDOGCALL

DOGCALL is capable of logging keystrokes.

T1057
Process Discovery
MalwareFinal1stspy

Final1stspy obtains a list of running processes.

T1071.001
Web Protocols
MalwareFinal1stspy

Final1stspy uses HTTP for C2.

T1082
System Information Discovery
MalwareFinal1stspy

Final1stspy obtains victim Microsoft Windows version information and CPU architecture.

T1102.002
Bidirectional Communication
MalwareDOGCALL

DOGCALL is capable of leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex for C2.

T1105
Ingress Tool Transfer
MalwareDOGCALL

DOGCALL can download and execute additional payloads.

T1113
Screen Capture
MalwareDOGCALL

DOGCALL is capable of capturing screenshots of the victim's machine.

T1123
Audio Capture
MalwareDOGCALL

DOGCALL can capture microphone data from the victim's machine.

T1140
Deobfuscate/Decode Files or Information
MalwareFinal1stspy

Final1stspy uses Python code to deobfuscate base64-encoded strings.

T1547.001
Registry Run Keys / Startup Folder
MalwareFinal1stspy

Final1stspy creates a Registry Run key to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.