Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareTroll Stealer | Troll Stealer gathers information from infected systems such as SSH information from the victim's `.ssh` directory. Troll Stealer collects information from local FileZilla installations and Microsoft Sticky Note. |
| T1016 System Network Configuration Discovery |
MalwareTroll Stealer | Troll Stealer collects the MAC address of victim devices. |
| T1027.002 Software Packing |
MalwareTroll Stealer | Troll Stealer has been delivered as a VMProtect-packed binary. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTroll Stealer | Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file. |
| T1041 Exfiltration Over C2 Channel |
MalwareTroll Stealer | Troll Stealer exfiltrates collected information to its command and control infrastructure. |
| T1059.001 PowerShell |
MalwareTroll Stealer | Troll Stealer creates and executes a PowerShell script to delete itself. |
| T1059.003 Windows Command Shell |
MalwareTroll Stealer | Troll Stealer can create and execute Windows batch scripts. |
| T1070.004 File Deletion |
MalwareTroll Stealer | Troll Stealer creates and can execute a BAT script that will delete the malware. |
| T1071.001 Web Protocols |
MalwareTroll Stealer | Troll Stealer uses HTTP to communicate to command and control infrastructure. |
| T1074.001 Local Data Staging |
MalwareTroll Stealer | Troll Stealer encrypts gathered information on victim devices prior to exfiltrating it through command and control infrastructure. |
| T1082 System Information Discovery |
MalwareTroll Stealer | Troll Stealer can collect local system information. |
| T1083 File and Directory Discovery |
MalwareTroll Stealer | Troll Stealer can enumerate and collect items from local drives and folders. |
| T1090 Proxy |
MalwareGoBear | GoBear implements SOCKS5 proxy functionality. |
| T1113 Screen Capture |
MalwareTroll Stealer | Troll Stealer can capture screenshots from victim machines. |
| T1132.001 Standard Encoding |
MalwareTroll Stealer | Troll Stealer performs XOR encryption and Base64 encoding of data prior to sending to command and control infrastructure. |
| T1213 Data from Information Repositories |
MalwareTroll Stealer | Troll Stealer gathers information from the Government Public Key Infrastructure (GPKI) folder, associated with South Korean government public key infrastructure, on infected systems. |
| T1217 Browser Information Discovery |
MalwareTroll Stealer | Troll Stealer collects information from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions. |
| T1218.011 Rundll32 |
MalwareTroll Stealer | Troll Stealer is dropped as a DLL file and executed via `rundll32.exe` by its installer. |
| T1480.002 Mutual Exclusion |
MalwareTroll Stealer | Troll Stealer creates a mutex during installation to prevent duplicate execution. |
| T1539 Steal Web Session Cookie |
GroupKimsuky | Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies. |
| T1552.004 Private Keys |
MalwareTroll Stealer | Troll Stealer collects all data in victim `.ssh` folders by creating a compressed copy that is subsequently exfiltrated to command and control infrastructure. Troll Stealer also collects key information associated with the Government Public Key Infrastructure (GPKI) service for South Korean government information systems. |
| T1553.002 Code Signing |
MalwareGoBear | GoBear uses stolen legitimate code signing certificates for defense evasion. |
| T1553.002 Code Signing |
MalwareTroll Stealer | Troll Stealer, along with its associated dropper, utilizes legitimate, stolen code signing certificates. |
| T1553.002 Code Signing |
GroupKimsuky | Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper. |
| T1560 Archive Collected Data |
MalwareTroll Stealer | Troll Stealer compresses stolen data prior to exfiltration. |
| T1573.001 Symmetric Cryptography |
MalwareTroll Stealer | Troll Stealer encrypts data sent to command and control infrastructure using a combination of RC4 and RSA-4096 algorithms. |
| T1588.003 Code Signing Certificates |
GroupKimsuky | Kimsuky has stolen a valid certificate that is used to sign the malware and the dropper. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.