ATT&CKReferencesPalo Alto Networks BBSRAT

Palo Alto Networks BBSRAT

Lee, B. Grunzweig, J. (2015, December 22). BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger. Retrieved August 19, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareBBSRAT

BBSRAT can query service configuration information.

T1055.012
Process Hollowing
MalwareBBSRAT

BBSRAT has been seen loaded into msiexec.exe through process hollowing to hide its execution.

T1057
Process Discovery
MalwareBBSRAT

BBSRAT can list running processes.

T1070.004
File Deletion
MalwareBBSRAT

BBSRAT can delete files and directories.

T1071.001
Web Protocols
MalwareBBSRAT

BBSRAT uses GET and POST requests over HTTP or HTTPS for command and control to obtain commands and send ZLIB compressed data back to the C2 server.

T1083
File and Directory Discovery
MalwareBBSRAT

BBSRAT can list file and directory information.

T1140
Deobfuscate/Decode Files or Information
MalwareBBSRAT

BBSRAT uses Expand to decompress a CAB file into executable content.

T1543.003
Windows Service
MalwareBBSRAT

BBSRAT can modify service configurations.

T1546.015
Component Object Model Hijacking
MalwareBBSRAT

BBSRAT has been seen persisting via COM hijacking through replacement of the COM object for MruPidlList {42aedc87-2188-41fd-b9a3-0c966feabec1} or Microsoft WBEM New Event Subsystem {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} depending on the system's CPU architecture.

T1560.002
Archive via Library
MalwareBBSRAT

BBSRAT can compress data with ZLIB prior to sending it back to the C2 server.

T1569.002
Service Execution
MalwareBBSRAT

BBSRAT can start, stop, or delete services.

T1573.001
Symmetric Cryptography
MalwareBBSRAT

BBSRAT uses a custom encryption algorithm on data sent back to the C2 server over HTTP.

T1574.001
DLL
MalwareBBSRAT

DLL side-loading has been used to execute BBSRAT through a legitimate Citrix executable, ssonsvr.exe. The Citrix executable was dropped along with BBSRAT by the dropper.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.