Lee, B. Grunzweig, J. (2015, December 22). BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger. Retrieved August 19, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareBBSRAT | BBSRAT can query service configuration information. |
| T1055.012 Process Hollowing |
MalwareBBSRAT | BBSRAT has been seen loaded into msiexec.exe through process hollowing to hide its execution. |
| T1057 Process Discovery |
MalwareBBSRAT | BBSRAT can list running processes. |
| T1070.004 File Deletion |
MalwareBBSRAT | BBSRAT can delete files and directories. |
| T1071.001 Web Protocols |
MalwareBBSRAT | BBSRAT uses GET and POST requests over HTTP or HTTPS for command and control to obtain commands and send ZLIB compressed data back to the C2 server. |
| T1083 File and Directory Discovery |
MalwareBBSRAT | BBSRAT can list file and directory information. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBBSRAT | BBSRAT uses Expand to decompress a CAB file into executable content. |
| T1543.003 Windows Service |
MalwareBBSRAT | BBSRAT can modify service configurations. |
| T1546.015 Component Object Model Hijacking |
MalwareBBSRAT | BBSRAT has been seen persisting via COM hijacking through replacement of the COM object for MruPidlList |
| T1560.002 Archive via Library |
MalwareBBSRAT | BBSRAT can compress data with ZLIB prior to sending it back to the C2 server. |
| T1569.002 Service Execution |
MalwareBBSRAT | BBSRAT can start, stop, or delete services. |
| T1573.001 Symmetric Cryptography |
MalwareBBSRAT | BBSRAT uses a custom encryption algorithm on data sent back to the C2 server over HTTP. |
| T1574.001 DLL |
MalwareBBSRAT | DLL side-loading has been used to execute BBSRAT through a legitimate Citrix executable, ssonsvr.exe. The Citrix executable was dropped along with BBSRAT by the dropper. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.