Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
CampaignKV Botnet Activity | KV Botnet Activity gathers victim IP information during initial installation stages. |
| T1036 Masquerading |
CampaignKV Botnet Activity | KV Botnet Activity involves changing process filename to |
| T1036.004 Masquerade Task or Service |
CampaignKV Botnet Activity | KV Botnet Activity installation steps include first identifying, then stopping, any process containing |
| T1055.009 Proc Memory |
CampaignKV Botnet Activity | KV Botnet Activity final payload installation includes mounting and binding to the |
| T1057 Process Discovery |
CampaignKV Botnet Activity | Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation. |
| T1059.004 Unix Shell |
CampaignKV Botnet Activity | KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell. |
| T1070.004 File Deletion |
CampaignKV Botnet Activity | KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device. |
| T1082 System Information Discovery |
CampaignKV Botnet Activity | KV Botnet Activity includes use of native system tools, such as |
| T1083 File and Directory Discovery |
CampaignKV Botnet Activity | KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: |
| T1095 Non-Application Layer Protocol |
CampaignKV Botnet Activity | KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication. |
| T1105 Ingress Tool Transfer |
CampaignKV Botnet Activity | KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes. |
| T1222.002 Linux and Mac Permissions |
CampaignKV Botnet Activity | KV Botnet Activity altered permissions on downloaded tools and payloads to enable execution on victim machines. |
| T1518.001 Security Software Discovery |
CampaignKV Botnet Activity | KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices. |
| T1546 Event Triggered Execution |
CampaignKV Botnet Activity | KV Botnet Activity involves managing events on victim systems via |
| T1564.013 Bind Mounts |
CampaignKV Botnet Activity | KV Botnet Activity leveraged a bind mount to bind itself to the `/proc/` file path before deleting its files from the `/tmp/` directory. |
| T1571 Non-Standard Port |
CampaignKV Botnet Activity | KV Botnet Activity generates a random port number greater than 30,000 to serve as the listener for subsequent command and control activity. |
| T1573 Encrypted Channel |
CampaignKV Botnet Activity | KV Botnet Activity command and control activity includes transmission of an RSA public key in communication from the server, but this is followed by subsequent negotiation stages that represent a form of handshake similar to TLS negotiation. |
| T1583.003 Virtual Private Server |
CampaignKV Botnet Activity | KV Botnet Activity used acquired Virtual Private Servers as control systems for devices infected with KV Botnet malware. |
| T1584.008 Network Devices |
CampaignKV Botnet Activity | KV Botnet Activity focuses on compromise of small office-home office (SOHO) network devices to build the subsequent botnet. |
| T1685 Disable or Modify Tools |
CampaignKV Botnet Activity | KV Botnet Activity used various scripts to remove or disable security tools, such as |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.