NKAbuse SL

KASPERSKY GERT. (2023, December 14). Unveiling NKAbuse: a new multiplatform threat abusing the NKN protocol. Retrieved February 8, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1016.001
Internet Connection Discovery
MalwareNKAbuse

NKAbuse utilizes external services such as ifconfig.me to identify the victim machine's IP address.

T1053.003
Cron
MalwareNKAbuse

NKAbuse uses a Cron job to establish persistence when infecting Linux hosts.

T1057
Process Discovery
MalwareNKAbuse

NKAbuse will check victim systems to ensure only one copy of the malware is running.

T1059.004
Unix Shell
MalwareNKAbuse

NKAbuse is initially installed and executed through an initial shell script.

T1082
System Information Discovery
MalwareNKAbuse

NKAbuse conducts multiple system checks and includes these in subsequent "heartbeat" messages to the malware's command and control server.

T1090.003
Multi-hop Proxy
MalwareNKAbuse

NKAbuse has abused the NKN public blockchain protocol for its C2 communications.

T1113
Screen Capture
MalwareNKAbuse

NKAbuse can take screenshots of the victim machine.

T1498
Network Denial of Service
MalwareNKAbuse

NKAbuse enables multiple types of network denial of service capabilities across several protocols post-installation.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.