ATT&CKReferencesESET InvisiMole June 2020

ESET InvisiMole June 2020

Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

Open the source

Techniques4

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples56

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareInvisiMole

InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP.

T1008
Fallback Channels
MalwareInvisiMole

InvisiMole has been configured with several servers available for alternate C2 communications.

T1010
Application Window Discovery
MalwareInvisiMole

InvisiMole can enumerate windows and child windows on a compromised host.

T1016
System Network Configuration Discovery
MalwareInvisiMole

InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID.

T1025
Data from Removable Media
MalwareInvisiMole

InvisiMole can collect jpeg files from connected MTP devices.

T1027
Obfuscated Files or Information
MalwareInvisiMole

InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format.

T1027.005
Indicator Removal from Tools
MalwareInvisiMole

InvisiMole has undergone regular technical improvements in an attempt to evade detection.

T1036.004
Masquerade Task or Service
MalwareInvisiMole

InvisiMole has attempted to disguise itself by registering under a seemingly legitimate service name.

T1036.005
Match Legitimate Resource Name or Location
MalwareInvisiMole

InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder.

T1046
Network Service Discovery
MalwareInvisiMole

InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols.

T1053.005
Scheduled Task
MalwareInvisiMole

InvisiMole has used scheduled tasks named MSST and \Microsoft\Windows\Autochk\Scheduled to establish persistence.

T1055
Process Injection
MalwareInvisiMole

InvisiMole can inject itself into another process to avoid detection including use of a technique called ListPlanting that customizes the sorting algorithm in a ListView structure.

T1055.002
Portable Executable Injection
MalwareInvisiMole

InvisiMole can inject its backdoor as a portable executable into a target process.

T1055.004
Asynchronous Procedure Call
MalwareInvisiMole

InvisiMole can inject its code into a trusted process via the APC queue.

T1055.015
ListPlanting
MalwareInvisiMole

InvisiMole has used ListPlanting to inject code into a trusted process.

T1056.001
Keylogging
MalwareInvisiMole

InvisiMole can capture keystrokes on a compromised host.

T1057
Process Discovery
MalwareInvisiMole

InvisiMole can obtain a list of running processes.

T1059.003
Windows Command Shell
MalwareInvisiMole

InvisiMole can launch a remote shell to execute commands.

T1059.007
JavaScript
MalwareInvisiMole

InvisiMole can use a JavaScript file as part of its execution chain.

T1068
Exploitation for Privilege Escalation
MalwareInvisiMole

InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges.

T1070.004
File Deletion
MalwareInvisiMole

InvisiMole has deleted files and directories including XML and files successfully uploaded to C2 servers.

T1071.004
DNS
MalwareInvisiMole

InvisiMole has used a custom implementation of DNS tunneling to embed C2 communications in DNS requests and replies.

T1074.001
Local Data Staging
MalwareInvisiMole

InvisiMole determines a working directory where it stores all the gathered data about the compromised machine.

T1080
Taint Shared Content
MalwareInvisiMole

InvisiMole can replace legitimate software or documents in the compromised network with their trojanized versions, in an attempt to propagate itself within the network.

T1082
System Information Discovery
MalwareInvisiMole

InvisiMole can gather information on the OS version, computer name, DEP policy, and memory size.

T1090.002
External Proxy
MalwareInvisiMole

InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication.

T1095
Non-Application Layer Protocol
MalwareInvisiMole

InvisiMole has used TCP to download additional modules.

T1105
Ingress Tool Transfer
MalwareInvisiMole

InvisiMole can upload files to the victim's machine for operations.

T1106
Native API
MalwareInvisiMole

InvisiMole can use winapiexec tool for indirect execution of ShellExecuteW and CreateProcessA.

T1112
Modify Registry
MalwareInvisiMole

InvisiMole has a command to create, set, copy, or delete a specified Registry key or value.

T1113
Screen Capture
MalwareInvisiMole

InvisiMole can capture screenshots of not only the entire screen, but of each separate window open, in case they are overlapping.

T1119
Automated Collection
MalwareInvisiMole

InvisiMole can sort and collect specific documents as well as generate a list of all files on a newly inserted drive and store them in an encrypted file.

T1123
Audio Capture
MalwareInvisiMole

InvisiMole can record sound using input audio devices.

T1124
System Time Discovery
MalwareInvisiMole

InvisiMole gathers the local system time from the victim’s machine.

T1125
Video Capture
MalwareInvisiMole

InvisiMole can remotely activate the victim’s webcam to capture content.

T1132.002
Non-Standard Encoding
MalwareInvisiMole

InvisiMole can use a modified base32 encoding to encode data within the subdomain of C2 requests.

T1140
Deobfuscate/Decode Files or Information
MalwareInvisiMole

InvisiMole can decrypt, unpack and load a DLL from its resources, or from blobs encrypted with Data Protection API, two-key triple DES, and variations of the XOR cipher.

T1203
Exploitation for Client Execution
MalwareInvisiMole

InvisiMole has installed legitimate but vulnerable Total Video Player software and wdigest.dll library drivers on compromised hosts to exploit stack overflow and input validation vulnerabilities for code execution.

T1204.002
Malicious File
MalwareInvisiMole

InvisiMole can deliver trojanized versions of software and documents, relying on user execution.

T1210
Exploitation of Remote Services
MalwareInvisiMole

InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively.

T1218.002
Control Panel
MalwareInvisiMole

InvisiMole can register itself for execution and persistence via the Control Panel.

T1218.011
Rundll32
MalwareInvisiMole

InvisiMole has used rundll32.exe for execution.

T1480.001
Environmental Keying
MalwareInvisiMole

InvisiMole can use Data Protection API to encrypt its components on the victim’s computer, to evade detection, and to make sure the payload can only be decrypted and loaded on one specific compromised computer.

T1497.001
System Checks
MalwareInvisiMole

InvisiMole can check for artifacts of VirtualBox, Virtual PC and VMware environment, and terminate itself if they are detected.

T1518
Software Discovery
MalwareInvisiMole

InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system.

T1518.001
Security Software Discovery
MalwareInvisiMole

InvisiMole can check for the presence of network sniffers, AV, and BitDefender firewall.

T1543.003
Windows Service
MalwareInvisiMole

InvisiMole can register a Windows service named CsPower as part of its execution chain, and a Windows service named clr_optimization_v2.0.51527_X86 to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareInvisiMole

InvisiMole can place a lnk file in the Startup Folder to achieve persistence.

T1547.009
Shortcut Modification
MalwareInvisiMole

InvisiMole can use a .lnk shortcut for the Control Panel to establish persistence.

T1548.002
Bypass User Account Control
MalwareInvisiMole

InvisiMole can use fileless UAC bypass and create an elevated COM object to escalate privileges.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.