ATT&CKReferencesUnit 42 BackConfig May 2020

Unit 42 BackConfig May 2020

Hinchliffe, A. and Falcone, R. (2020, May 11). Updated BackConfig Malware Targeting Government and Military Organizations in South Asia. Retrieved June 17, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareBackConfig

BackConfig has used compressed and decimal encoded VBS scripts.

T1036.005
Match Legitimate Resource Name or Location
MalwareBackConfig

BackConfig has hidden malicious payloads in %USERPROFILE%\Adobe\Driver\dwg\ and mimicked the legitimate DHCP service binary.

T1053.005
Scheduled Task
MalwareBackConfig

BackConfig has the ability to use scheduled tasks to repeatedly execute malicious payloads on a compromised host.

T1059.003
Windows Command Shell
MalwareBackConfig

BackConfig can download and run batch files to execute commands on a compromised host.

T1059.005
Visual Basic
MalwareBackConfig

BackConfig has used VBS to install its downloader component and malicious documents with VBA macro code.

T1070.004
File Deletion
MalwareBackConfig

BackConfig has the ability to remove files and folders related to previous infections.

T1071.001
Web Protocols
MalwareBackConfig

BackConfig has the ability to use HTTPS for C2 communiations.

T1082
System Information Discovery
MalwareBackConfig

BackConfig has the ability to gather the victim's computer name.

T1083
File and Directory Discovery
MalwareBackConfig

BackConfig has the ability to identify folders and files related to previous infections.

T1105
Ingress Tool Transfer
MalwareBackConfig

BackConfig can download and execute additional payloads on a compromised host.

T1106
Native API
MalwareBackConfig

BackConfig can leverage API functions such as ShellExecuteA and HttpOpenRequestA in the process of downloading and executing files.

T1137.001
Office Template Macros
MalwareBackConfig

BackConfig has the ability to use hidden columns in Excel spreadsheets to store executable files or commands for VBA macros.

T1140
Deobfuscate/Decode Files or Information
MalwareBackConfig

BackConfig has used a custom routine to decrypt strings.

T1197
BITS Jobs
GroupPatchwork

Patchwork has used BITS jobs to download malicious payloads.

T1203
Exploitation for Client Execution
GroupPatchwork

Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641.

T1204.001
Malicious Link
MalwareBackConfig

BackConfig has compromised victims via links to URLs hosting malicious content.

T1204.001
Malicious Link
GroupPatchwork

Patchwork has used spearphishing with links to try to get users to click, download and open malicious files.

T1553.002
Code Signing
GroupPatchwork

Patchwork has signed malware with self-signed certificates from fictitious and spoofed legitimate software companies.

T1553.002
Code Signing
MalwareBackConfig

BackConfig has been signed with self signed digital certificates mimicking a legitimate software company.

T1564.001
Hidden Files and Directories
MalwareBackConfig

BackConfig has the ability to set folders or files to be hidden from the Windows Explorer default view.

T1566.002
Spearphishing Link
GroupPatchwork

Patchwork has used spearphishing with links to deliver files with exploits to initial victims.

T1587.002
Code Signing Certificates
GroupPatchwork

Patchwork has created self-signed certificates from fictitious and spoofed legitimate software companies that were later used to sign malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.