RARSTONE

S0055

Malware.View on attack.mitre.org

About this malware

RARSTONE is malware used by the Naikon group that has some characteristics similar to PlugX.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1055.001
Dynamic-link Library Injection

After decrypting itself in memory, RARSTONE downloads a DLL file from its C2 server and loads it in the memory space of a hidden Internet Explorer process. This “downloaded” file is actually not dropped onto the system.

T1083
File and Directory Discovery

RARSTONE obtains installer properties from Uninstall Registry Key entries to obtain information about installed applications and how to uninstall certain applications.

T1095
Non-Application Layer Protocol

RARSTONE uses SSL to encrypt its communication with its C2 server.

T1105
Ingress Tool Transfer

RARSTONE downloads its backdoor component from a C2 server and loads it directly into memory.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Aquino RARSTONE Open source
    Aquino, M. (2013, June 13). RARSTONE Found In Targeted Attacks. Retrieved December 17, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.