ATT&CKReferencesTalos PoetRAT April 2020

Talos PoetRAT April 2020

Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwarePoetRAT

PoetRAT used voStro.exe, a compiled pypykatz (Python version of Mimikatz), to steal credentials.

T1018
Remote System Discovery
MalwarePoetRAT

PoetRAT used Nmap for remote system discovery.

T1027
Obfuscated Files or Information
MalwarePoetRAT

PoetRAT has used a custom encryption scheme for communication between scripts.

T1033
System Owner/User Discovery
MalwarePoetRAT

PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2.

T1048
Exfiltration Over Alternative Protocol
MalwarePoetRAT

PoetRAT has used a .NET tool named dog.exe to exiltrate information over an e-mail account.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwarePoetRAT

PoetRAT has used ftp for exfiltration.

T1056.001
Keylogging
MalwarePoetRAT

PoetRAT has used a Python tool named klog.exe for keylogging.

T1057
Process Discovery
MalwarePoetRAT

PoetRAT has the ability to list all running processes.

T1059.005
Visual Basic
MalwarePoetRAT

PoetRAT has used Word documents with VBScripts to execute malicious activities.

T1059.006
Python
MalwarePoetRAT

PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools.

T1070.004
File Deletion
MalwarePoetRAT

PoetRAT has the ability to overwrite scripts and delete itself if a sandbox environment is detected.

T1082
System Information Discovery
MalwarePoetRAT

PoetRAT has the ability to gather information about the compromised host.

T1083
File and Directory Discovery
MalwarePoetRAT

PoetRAT has the ability to list files upon receiving the ls command from C2.

T1105
Ingress Tool Transfer
MalwarePoetRAT

PoetRAT has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS.

T1112
Modify Registry
MalwarePoetRAT

PoetRAT has made registry modifications to alter its behavior upon execution.

T1113
Screen Capture
MalwarePoetRAT

PoetRAT has the ability to take screen captures.

T1119
Automated Collection
MalwarePoetRAT

PoetRAT used file system monitoring to track modification and enable automatic exfiltration.

T1125
Video Capture
MalwarePoetRAT

PoetRAT has used a Python tool named Bewmac to record the webcam on compromised hosts.

T1204.002
Malicious File
MalwarePoetRAT

PoetRAT has used spearphishing attachments to infect victims.

T1497.001
System Checks
MalwarePoetRAT

PoetRAT checked the size of the hard drive to determine if it was being run in a sandbox environment. In the event of sandbox detection, it would delete itself by overwriting the malware scripts with the contents of "License.txt" and exiting.

T1547.001
Registry Run Keys / Startup Folder
MalwarePoetRAT

PoetRAT has added a registry key in the <RUN> hive for persistence.

T1555.003
Credentials from Web Browsers
MalwarePoetRAT

PoetRAT has used a Python tool named Browdec.exe to steal browser credentials.

T1559.002
Dynamic Data Exchange
MalwarePoetRAT

PoetRAT was delivered with documents using DDE to execute malicious code.

T1560.001
Archive via Utility
MalwarePoetRAT

PoetRAT has the ability to compress files with zip.

T1564.001
Hidden Files and Directories
MalwarePoetRAT

PoetRAT has the ability to hide and unhide files.

T1566.001
Spearphishing Attachment
MalwarePoetRAT

PoetRAT was distributed via malicious Word documents.

T1571
Non-Standard Port
MalwarePoetRAT

PoetRAT used TLS to encrypt communications over port 143

T1573.002
Asymmetric Cryptography
MalwarePoetRAT

PoetRAT used TLS to encrypt command and control (C2) communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.