ATT&CKReferencesPaloAlto CardinalRat Apr 2017

PaloAlto CardinalRat Apr 2017

Grunzweig, J.. (2017, April 20). Cardinal RAT Active for Over Two Years. Retrieved December 8, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareCardinal RAT

Cardinal RAT can communicate over multiple C2 host and port combinations.

T1012
Query Registry
MalwareCardinal RAT

Cardinal RAT contains watchdog functionality that periodically ensures HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load is set to point to its executable.

T1027.004
Compile After Delivery
MalwareCardinal RAT

Cardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code.

T1027.013
Encrypted/Encoded File
MalwareCardinal RAT

Cardinal RAT encodes many of its artifacts and is encrypted (AES-128) when downloaded.

T1033
System Owner/User Discovery
MalwareCardinal RAT

Cardinal RAT can collect the username from a victim machine.

T1055
Process Injection
MalwareCardinal RAT

Cardinal RAT injects into a newly spawned process created from a native Windows executable.

T1056.001
Keylogging
MalwareCardinal RAT

Cardinal RAT can log keystrokes.

T1057
Process Discovery
MalwareCardinal RAT

Cardinal RAT contains watchdog functionality that ensures its process is always running, else spawns a new instance.

T1059.003
Windows Command Shell
MalwareCardinal RAT

Cardinal RAT can execute commands.

T1070.004
File Deletion
MalwareCardinal RAT

Cardinal RAT can uninstall itself, including deleting its executable.

T1071.001
Web Protocols
MalwareCardinal RAT

Cardinal RAT is downloaded using HTTP over port 443.

T1082
System Information Discovery
MalwareCardinal RAT

Cardinal RAT can collect the hostname, Microsoft Windows version, and processor architecture from a victim machine.

T1083
File and Directory Discovery
MalwareCardinal RAT

Cardinal RAT checks its current working directory upon execution and also contains watchdog functionality that ensures its executable is located in the correct path (else it will rewrite the payload).

T1090
Proxy
MalwareCardinal RAT

Cardinal RAT can act as a reverse proxy.

T1105
Ingress Tool Transfer
MalwareCardinal RAT

Cardinal RAT can download and execute additional payloads.

T1112
Modify Registry
MalwareCardinal RAT

Cardinal RAT sets HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load to point to its executable.

T1113
Screen Capture
MalwareCardinal RAT

Cardinal RAT can capture screenshots.

T1140
Deobfuscate/Decode Files or Information
MalwareCardinal RAT

Cardinal RAT decodes many of its artifacts and is decrypted (AES-128) after being downloaded.

T1204.002
Malicious File
MalwareCardinal RAT

Cardinal RAT lures victims into executing malicious macros embedded within Microsoft Excel documents.

T1547.001
Registry Run Keys / Startup Folder
MalwareCardinal RAT

Cardinal RAT establishes Persistence by setting the HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load Registry key to point to its executable.

T1560.002
Archive via Library
MalwareCardinal RAT

Cardinal RAT applies compression to C2 traffic using the ZLIB library.

T1573.001
Symmetric Cryptography
MalwareCardinal RAT

Cardinal RAT uses a secret key with a series of XOR and addition operations to encrypt C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.