ATT&CKReferencesUnit42 Redaman January 2019

Unit42 Redaman January 2019

Duncan, B., Harbison, M. (2019, January 23). Russian Language Malspam Pushing Redaman Banking Malware. Retrieved June 16, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareRTM

RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm.

T1027.015
Compression
MalwareRTM

RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR.

T1036
Masquerading
MalwareRTM

RTM has been delivered as archived Windows executable files masquerading as PDF documents.

T1036.004
Masquerade Task or Service
MalwareRTM

RTM has named the scheduled task it creates "Windows Update".

T1053.005
Scheduled Task
MalwareRTM

RTM tries to add a scheduled task to establish persistence.

T1056.001
Keylogging
MalwareRTM

RTM can record keystrokes from both the keyboard and virtual keyboard.

T1070.004
File Deletion
MalwareRTM

RTM can delete all files created during its execution.

T1071.001
Web Protocols
MalwareRTM

RTM has initiated connections to external domains using HTTPS.

T1083
File and Directory Discovery
MalwareRTM

RTM can check for specific files and directories associated with virtualization and malware analysis.

T1102.001
Dead Drop Resolver
MalwareRTM

RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain.

T1105
Ingress Tool Transfer
MalwareRTM

RTM can download additional files.

T1113
Screen Capture
MalwareRTM

RTM can capture screenshots.

T1115
Clipboard Data
MalwareRTM

RTM collects data from the clipboard.

T1119
Automated Collection
MalwareRTM

RTM monitors browsing activity and automatically captures screenshots if a victim browses to a URL matching one of a list of strings.

T1120
Peripheral Device Discovery
MalwareRTM

RTM can obtain a list of smart card readers attached to the victim.

T1204.002
Malicious File
MalwareRTM

RTM has relied on users opening malicious email attachments, decompressing the attached archive, and double-clicking the executable within.

T1218.011
Rundll32
MalwareRTM

RTM runs its core DLL file using rundll32.exe.

T1497
Virtualization/Sandbox Evasion
MalwareRTM

RTM can detect if it is running within a sandbox or other virtualized analysis environment.

T1553.004
Install Root Certificate
MalwareRTM

RTM can add a certificate to the Windows store.

T1566.001
Spearphishing Attachment
MalwareRTM

RTM has been delivered via spearphishing attachments disguised as PDF documents.

T1568
Dynamic Resolution
MalwareRTM

RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.