ATT&CKReferencesMcAfee Gold Dragon

McAfee Gold Dragon

Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples31

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareGold Dragon

Gold Dragon enumerates registry keys with the command regkeyenum and obtains information for the Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

T1012
Query Registry
MalwareBrave Prince

Brave Prince gathers information about the Registry.

T1016
System Network Configuration Discovery
MalwareBrave Prince

Brave Prince gathers network configuration information as well as the ARP cache.

T1033
System Owner/User Discovery
MalwareGold Dragon

Gold Dragon collects the endpoint victim's username and uses it as a basis for downloading additional components from the C2 server.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareBrave Prince

Some Brave Prince variants have used South Korea's Daum email service to exfiltrate information, and later variants have posted the data to a web server via an HTTP post command.

T1056.001
Keylogging
MalwareRunningRAT

RunningRAT captures keystrokes and sends them back to the C2 server.

T1057
Process Discovery
MalwareGold Dragon

Gold Dragon checks the running processes on the victim’s machine.

T1057
Process Discovery
MalwareBrave Prince

Brave Prince lists the running processes.

T1059.003
Windows Command Shell
MalwareRunningRAT

RunningRAT uses a batch file to kill a security program task and then attempts to remove itself.

T1059.003
Windows Command Shell
MalwareGold Dragon

Gold Dragon uses cmd.exe to execute commands for discovery.

T1070.004
File Deletion
MalwareRunningRAT

RunningRAT contains code to delete files from the victim’s machine.

T1070.004
File Deletion
MalwareGold Dragon

Gold Dragon deletes one of its files, 2.hwp, from the endpoint after establishing persistence.

T1071.001
Web Protocols
MalwareGold Dragon

Gold Dragon uses HTTP for communication to the control servers.

T1074.001
Local Data Staging
MalwareGold Dragon

Gold Dragon stores information gathered from the endpoint in a file named 1.hwp.

T1082
System Information Discovery
MalwareRunningRAT

RunningRAT gathers the OS version and processor information.

T1082
System Information Discovery
MalwareBrave Prince

Brave Prince collects hard drive content and system configuration information.

T1082
System Information Discovery
MalwareGold Dragon

Gold Dragon collects endpoint information using the systeminfo command.

T1083
File and Directory Discovery
MalwareGold Dragon

Gold Dragon lists the directories for Desktop, program files, and the user’s recently accessed files.

T1083
File and Directory Discovery
MalwareBrave Prince

Brave Prince gathers file and directory information from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareGold Dragon

Gold Dragon can download additional components from the C2 server.

T1115
Clipboard Data
MalwareRunningRAT

RunningRAT contains code to open and copy data from the clipboard.

T1518.001
Security Software Discovery
MalwareGold Dragon

Gold Dragon checks for anti-malware products and processes.

T1547.001
Registry Run Keys / Startup Folder
MalwareGold Dragon

Gold Dragon establishes persistence in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareRunningRAT

RunningRAT adds itself to the Registry key Software\Microsoft\Windows\CurrentVersion\Run to establish persistence upon reboot.

T1560
Archive Collected Data
MalwareRunningRAT

RunningRAT contains code to compress files.

T1560
Archive Collected Data
MalwareGold Dragon

Gold Dragon encrypts data using Base64 before being sent to the command and control server.

T1680
Local Storage Discovery
MalwareRunningRAT

RunningRAT gathers logical drives information and volume information.

T1685
Disable or Modify Tools
MalwareGold Dragon

Gold Dragon terminates anti-malware processes if they’re found running on the system.

T1685
Disable or Modify Tools
MalwareBrave Prince

Brave Prince terminates antimalware processes.

T1685
Disable or Modify Tools
MalwareRunningRAT

RunningRAT kills antimalware running process.

T1685.005
Clear Windows Event Logs
MalwareRunningRAT

RunningRAT contains code to clear event logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.