ATT&CKSoftwareBLACKCOFFEE

BLACKCOFFEE

S0069

Malware.View on attack.mitre.org

About this malware

BLACKCOFFEE is malware that has been used by several Chinese groups since at least 2013.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1057
Process Discovery

BLACKCOFFEE has the capability to discover processes.

T1059.003
Windows Command Shell

BLACKCOFFEE has the capability to create a reverse shell.

T1070.004
File Deletion

BLACKCOFFEE has the capability to delete files.

T1083
File and Directory Discovery

BLACKCOFFEE has the capability to enumerate files.

T1102.001
Dead Drop Resolver

BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain a dead drop resolver containing an encoded tag with the IP address of a command and control server.

T1102.002
Bidirectional Communication

BLACKCOFFEE has also obfuscated its C2 traffic as normal traffic to sites such as Github.

T1104
Multi-Stage Channels

BLACKCOFFEE uses Microsoft’s TechNet Web portal to obtain an encoded tag containing the IP address of a command and control server and then communicates separately with that IP address for C2. If the C2 server is discovered or shut down, the threat actors can update the encoded IP address on TechNet to maintain control of the victims’ machines.

Groups that use it3

Campaigns0

None recorded.

References2

  1. FireEye APT17 Open source
    FireEye Labs/FireEye Threat Intelligence. (2015, May 14). Hiding in Plain Sight: FireEye and Microsoft Expose Obfuscation Tactic. Retrieved November 17, 2024.
  2. FireEye Periscope March 2018 Open source
    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.