LOWBALL

S0042

Malware.View on attack.mitre.org

About this malware

LOWBALL is malware used by admin@338. It was used in August 2015 in email messages targeting Hong Kong-based media organizations.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1071.001
Web Protocols

LOWBALL command and control occurs via HTTPS over port 443.

T1102.002
Bidirectional Communication

LOWBALL uses the Dropbox cloud storage service for command and control.

T1105
Ingress Tool Transfer

LOWBALL uses the Dropbox API to request two files, one of which is the same file as the one dropped by the malicious email attachment. This is most likely meant to be a mechanism to update the compromised host with a new version of the LOWBALL malware.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye admin@338 Open source
    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.