ATT&CKReferencesBleepingComputer Molerats Dec 2020

BleepingComputer Molerats Dec 2020

Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareSharpStage

SharpStage can use WMI for execution.

T1059.001
PowerShell
MalwareSharpStage

SharpStage can execute arbitrary commands with PowerShell.

T1059.003
Windows Command Shell
MalwareSharpStage

SharpStage can execute arbitrary commands with the command line.

T1059.003
Windows Command Shell
MalwareDropBook

DropBook can execute arbitrary shell commands on the victims' machines.

T1082
System Information Discovery
MalwareSharpStage

SharpStage has checked the system settings to see if Arabic is the configured language.

T1083
File and Directory Discovery
MalwareDropBook

DropBook can collect the names of all files and folders in the Program Files directories.

T1102
Web Service
MalwareDropBook

DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions.

T1105
Ingress Tool Transfer
MalwareDropBook

DropBook can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareSharpStage

SharpStage has the ability to download and execute additional payloads via a DropBox API.

T1113
Screen Capture
MalwareSharpStage

SharpStage has the ability to capture the victim's screen.

T1140
Deobfuscate/Decode Files or Information
MalwareSharpStage

SharpStage has decompressed data received from the C2 server.

T1567
Exfiltration Over Web Service
MalwareDropBook

DropBook has used legitimate web services to exfiltrate data.

T1614.001
System Language Discovery
MalwareDropBook

DropBook has checked for the presence of Arabic language in the infected machine's settings.

T1614.001
System Language Discovery
MalwareSharpStage

SharpStage has been used to target Arabic-speaking users and used code that checks if the compromised machine has the Arabic language installed.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.