ATT&CKReferencesESET Kobalos Feb 2021

ESET Kobalos Feb 2021

M.Leveille, M., Sanmillan, I. (2021, February 2). Kobalos – A complex Linux threat to high performance computing infrastructure. Retrieved August 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareKobalos

Kobalos encrypts all strings using RC4 and bundles all functionality into a single function call.

T1056
Input Capture
MalwareKobalos

Kobalos has used a compromised SSH client to capture the hostname, port, username and password used to establish an SSH connection from the compromised host.

T1059.004
Unix Shell
MalwareKobalos

Kobalos can spawn a new pseudo-terminal and execute arbitrary commands at the command prompt.

T1070.003
Clear Command History
MalwareKobalos

Kobalos can remove all command history on compromised hosts.

T1090.003
Multi-hop Proxy
MalwareKobalos

Kobalos can chain together multiple compromised machines as proxies to reach their final targets.

T1205
Traffic Signaling
MalwareKobalos

Kobalos is triggered by an incoming TCP connection to a legitimate service from a specific source port.

T1573.001
Symmetric Cryptography
MalwareKobalos

Kobalos's post-authentication communication channel uses a 32-byte-long password with RC4 for inbound and outbound traffic.

T1573.002
Asymmetric Cryptography
MalwareKobalos

Kobalos's authentication and key exchange is performed using RSA-512.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.