ATT&CKReferencesUnit42 BabyShark Apr 2019

Unit42 BabyShark Apr 2019

Lim, M.. (2019, April 26). BabyShark Malware Part Two – Attacks Continue Using KimJongRAT and PCRat . Retrieved October 7, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareBabyShark

BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger.

T1070.004
File Deletion
MalwareBabyShark

BabyShark has cleaned up all files associated with the secondary payload execution.

T1105
Ingress Tool Transfer
MalwareBabyShark

BabyShark has downloaded additional files from the C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.