ATT&CKReferencesESET Kobalos Jan 2021

ESET Kobalos Jan 2021

M.Leveille, M., Sanmillan, I. (2021, January). A WILD KOBALOS APPEARS Tricksy Linux malware goes after HPCs. Retrieved August 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareKobalos

Kobalos can record the IP address of the target machine.

T1048
Exfiltration Over Alternative Protocol
MalwareKobalos

Kobalos can exfiltrate credentials over the network via UDP.

T1056
Input Capture
MalwareKobalos

Kobalos has used a compromised SSH client to capture the hostname, port, username and password used to establish an SSH connection from the compromised host.

T1070.006
Timestomp
MalwareKobalos

Kobalos can modify timestamps of replaced files, such as ssh with the added credential stealer or sshd used to deploy Kobalos.

T1074
Data Staged
MalwareKobalos

Kobalos can write captured SSH connection credentials to a file under the /var/run directory with a .pid extension for exfiltration.

T1082
System Information Discovery
MalwareKobalos

Kobalos can record the hostname and kernel version of the target machine.

T1090.003
Multi-hop Proxy
MalwareKobalos

Kobalos can chain together multiple compromised machines as proxies to reach their final targets.

T1140
Deobfuscate/Decode Files or Information
MalwareKobalos

Kobalos decrypts strings right after the initial communication, but before the authentication process.

T1205
Traffic Signaling
MalwareKobalos

Kobalos is triggered by an incoming TCP connection to a legitimate service from a specific source port.

T1554
Compromise Host Software Binary
MalwareKobalos

Kobalos replaced the SSH client with a trojanized SSH client to steal credentials on compromised systems.

T1573.001
Symmetric Cryptography
MalwareKobalos

Kobalos's post-authentication communication channel uses a 32-byte-long password with RC4 for inbound and outbound traffic.

T1573.002
Asymmetric Cryptography
MalwareKobalos

Kobalos's authentication and key exchange is performed using RSA-512.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.