BISCUIT

S0017

Malware.View on attack.mitre.org

About this malware

BISCUIT is a backdoor that has been used by APT1 since as early as 2007.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1008
Fallback Channels

BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.

T1033
System Owner/User Discovery

BISCUIT has a command to gather the username from the system.

T1056.001
Keylogging

BISCUIT can capture keystrokes.

T1057
Process Discovery

BISCUIT has a command to enumerate running processes and identify their owners.

T1059.003
Windows Command Shell

BISCUIT has a command to launch a command shell on the system.

T1082
System Information Discovery

BISCUIT has a command to collect the processor type, operation system, computer name, and whether the system is a laptop or PC.

T1105
Ingress Tool Transfer

BISCUIT has a command to download a file from the C2 server.

T1113
Screen Capture

BISCUIT has a command to periodically take screenshots of the system.

T1124
System Time Discovery

BISCUIT has a command to collect the system `UPTIME`.

T1573.002
Asymmetric Cryptography

BISCUIT uses SSL for encrypting C2 communications.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant APT1 Open source
    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.