ATT&CKReferencesProofpoint ZeroT Feb 2017

Proofpoint ZeroT Feb 2017

Huss, D., et al. (2017, February 2). Oops, they did it again: APT Targets Russia and Belarus with ZeroT and PlugX. Retrieved April 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareZeroT

ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography.

T1016
System Network Configuration Discovery
MalwareZeroT

ZeroT gathers the victim's IP address and domain information, and then sends it to its C2 server.

T1027.002
Software Packing
MalwareZeroT

Some ZeroT DLL files have been packed with UPX.

T1027.013
Encrypted/Encoded File
MalwareZeroT

ZeroT has encrypted its payload with RC4.

T1027.016
Junk Code Insertion
MalwareZeroT

ZeroT has obfuscated DLLs and functions using dummy API calls inserted between real instructions.

T1071.001
Web Protocols
MalwareZeroT

ZeroT has used HTTP for C2.

T1082
System Information Discovery
MalwareZeroT

ZeroT gathers the victim's computer name, Windows version, and system language, and then sends it to its C2 server.

T1105
Ingress Tool Transfer
MalwareZeroT

ZeroT can download additional payloads onto the victim.

T1140
Deobfuscate/Decode Files or Information
MalwareZeroT

ZeroT shellcode decrypts and decompresses its RC4-encrypted payload.

T1543.003
Windows Service
MalwarePlugX

PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services.

T1543.003
Windows Service
MalwareZeroT

ZeroT can add a new service to ensure PlugX persists on the system when delivered as another payload onto the system.

T1548.002
Bypass User Account Control
MalwareZeroT

Many ZeroT samples can perform UAC bypass by using eventvwr.exe to execute a malicious file.

T1573.001
Symmetric Cryptography
MalwareZeroT

ZeroT has used RC4 to encrypt C2 traffic.

T1574.001
DLL
MalwareZeroT

ZeroT has used DLL side-loading to load malicious payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.