ATT&CKReferencesSecurelist ScarCruft May 2019

Securelist ScarCruft May 2019

GReAT. (2019, May 13). ScarCruft continues to evolve, introduces Bluetooth harvester. Retrieved June 4, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupAPT37

APT37 obfuscates strings and payloads.

T1027.003
Steganography
GroupAPT37

APT37 uses steganography to send images to users that are embedded with shellcode.

T1082
System Information Discovery
MalwareROKRAT

ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems.

T1083
File and Directory Discovery
MalwareROKRAT

ROKRAT has the ability to gather a list of files and directories on the infected system.

T1102.002
Bidirectional Communication
MalwareROKRAT

ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications.

T1105
Ingress Tool Transfer
GroupAPT37

APT37 has downloaded second stage malware from compromised websites.

T1113
Screen Capture
MalwareROKRAT

ROKRAT can capture screenshots of the infected system using the `gdi32` library.

T1120
Peripheral Device Discovery
GroupAPT37

APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.

T1123
Audio Capture
MalwareROKRAT

ROKRAT has an audio capture and eavesdropping module.

T1548.002
Bypass User Account Control
GroupAPT37

APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges.

T1566.001
Spearphishing Attachment
GroupAPT37

APT37 delivers malware using spearphishing emails with malicious HWP attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.