SslMM

S0058

Malware.View on attack.mitre.org

About this malware

SslMM is a full-featured backdoor used by Naikon that has multiple variants.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1008
Fallback Channels

SslMM has a hard-coded primary and backup C2 string.

T1033
System Owner/User Discovery

SslMM sends the logged-on username to its hard-coded C2.

T1036.005
Match Legitimate Resource Name or Location

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1056.001
Keylogging

SslMM creates a new thread implementing a keylogging facility using Windows Keyboard Accelerators.

T1082
System Information Discovery

SslMM sends information to its hard-coded C2, including OS version, service pack information, processor speed, system name, and OS install date.

T1134
Access Token Manipulation

SslMM contains a feature to manipulate process privileges and tokens.

T1547.001
Registry Run Keys / Startup Folder

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1547.009
Shortcut Modification

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1685
Disable or Modify Tools

SslMM identifies and kills anti-malware processes.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Baumgartner Naikon 2015 Open source
    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.