Cash, D., Grunzweig, J., Adair, S., Lancaster, T. (2021, August 25). North Korean BLUELIGHT Special: InkySquid Deploys RokRAT. Retrieved October 1, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareROKRAT | ROKRAT can collect host data and specific file types. |
| T1027 Obfuscated Files or Information |
MalwareROKRAT | ROKRAT can encrypt data prior to exfiltration by using an RSA public key. |
| T1027 Obfuscated Files or Information |
GroupAPT37 | APT37 obfuscates strings and payloads. |
| T1053.005 Scheduled Task |
GroupAPT37 | APT37 has created scheduled tasks to run malicious scripts on a compromised host. |
| T1056.001 Keylogging |
MalwareROKRAT | ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes. |
| T1059 Command and Scripting Interpreter |
GroupAPT37 | APT37 has used Ruby scripts to execute payloads. |
| T1059.006 Python |
GroupAPT37 | APT37 has used Python scripts to execute payloads. |
| T1082 System Information Discovery |
MalwareROKRAT | ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems. |
| T1083 File and Directory Discovery |
MalwareROKRAT | ROKRAT has the ability to gather a list of files and directories on the infected system. |
| T1102.002 Bidirectional Communication |
MalwareROKRAT | ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications. |
| T1105 Ingress Tool Transfer |
GroupAPT37 | APT37 has downloaded second stage malware from compromised websites. |
| T1105 Ingress Tool Transfer |
MalwareROKRAT | ROKRAT can retrieve additional malicious payloads from its C2 server. |
| T1115 Clipboard Data |
MalwareROKRAT | ROKRAT can extract clipboard data from a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareROKRAT | ROKRAT can decrypt strings using the victim's hostname as the key. |
| T1480.001 Environmental Keying |
MalwareROKRAT | ROKRAT relies on a specific victim hostname to execute and decrypt important strings. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareROKRAT | ROKRAT can send collected data to cloud storage services such as PCloud. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.