JHUHUGIT

S0044

Malware.View on attack.mitre.org

About this malware

JHUHUGIT is malware used by APT28. It is based on Carberp source code and serves as reconnaissance malware.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1008
Fallback Channels

JHUHUGIT tests if it can reach its C2 server by first attempting a direct connection, and if it fails, obtaining proxy settings and sending the connection through a proxy, and finally injecting code into a running browser if the proxy method fails.

T1016
System Network Configuration Discovery

A JHUHUGIT variant gathers network interface card information.

T1027.013
Encrypted/Encoded File

Many strings in JHUHUGIT are obfuscated with a XOR algorithm.

T1037.001
Logon Script (Windows)

JHUHUGIT has registered a Windows shell script under the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1053.005
Scheduled Task

JHUHUGIT has registered itself as a scheduled task to run each time the current user logs in.

T1055
Process Injection

JHUHUGIT performs code injection injecting its own functions to browser processes.

T1057
Process Discovery

JHUHUGIT obtains a list of running processes on the victim.

T1059.003
Windows Command Shell

JHUHUGIT uses a .bat file to execute a .dll.

T1068
Exploitation for Privilege Escalation

JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges.

T1070.004
File Deletion

The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files.

T1071.001
Web Protocols

JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS.

T1105
Ingress Tool Transfer

JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine.

T1113
Screen Capture

A JHUHUGIT variant takes screenshots by simulating the user pressing the "Take Screenshot" key (VK_SCREENSHOT), accessing the screenshot saved in the clipboard, and converting it to a JPG image.

T1115
Clipboard Data

A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image.

T1132.001
Standard Encoding

A JHUHUGIT variant encodes C2 POST data base64.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. ESET Sednit Part 1 Open source
    ESET. (2016, October). En Route with Sednit - Part 1: Approaching the Target. Retrieved November 8, 2016.
  2. F-Secure Sofacy 2015 Open source
    F-Secure. (2015, September 8). Sofacy Recycles Carberp and Metasploit Code. Retrieved August 3, 2016.
  3. FireEye APT28 January 2017 Open source
    FireEye iSIGHT Intelligence. (2017, January 11). APT28: At the Center of the Storm. Retrieved November 17, 2024.
  4. Kaspersky Sofacy Open source
    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.