CHOPSTICK

S0023

Malware.View on attack.mitre.org

About this malware

CHOPSTICK is a malware family of modular backdoors used by APT28. It has been used since at least 2012 and is usually dropped on victims as second-stage malware, though it has been used as first-stage malware in several cases. It has both Windows and Linux variants. It is tracked separately from the X-Agent for Android.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1008
Fallback Channels

CHOPSTICK can switch to a new C2 channel if the current one is broken.

T1012
Query Registry

CHOPSTICK provides access to the Windows Registry, which can be used to gather information.

T1027.011
Fileless Storage

CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry.

T1056.001
Keylogging

CHOPSTICK is capable of performing keylogging.

T1059
Command and Scripting Interpreter

CHOPSTICK is capable of performing remote command execution.

T1071.001
Web Protocols

Various implementations of CHOPSTICK communicate with C2 over HTTP.

T1071.003
Mail Protocols

Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3.

T1083
File and Directory Discovery

An older version of CHOPSTICK has a module that monitors all mounted volumes for files with the extensions .doc, .docx, .pgp, .gpg, .m2f, or .m2o.

T1090.001
Internal Proxy

CHOPSTICK used a proxy server between victims and the C2 server.

T1091
Replication Through Removable Media

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic.

T1092
Communication Through Removable Media

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic.

T1105
Ingress Tool Transfer

CHOPSTICK is capable of performing remote file transmission.

T1112
Modify Registry

CHOPSTICK may modify Registry keys to store RC4 encrypted configuration information.

T1113
Screen Capture

CHOPSTICK has the capability to capture screenshots.

T1497
Virtualization/Sandbox Evasion

CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. DOJ GRU Indictment Jul 2018 Open source
    Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.
  2. ESET Sednit Part 2 Open source
    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.
  3. FireEye APT28 Open source
    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.
  4. FireEye APT28 January 2017 Open source
    FireEye iSIGHT Intelligence. (2017, January 11). APT28: At the Center of the Storm. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.