Sakula

S0074

Malware.View on attack.mitre.org

About this malware

Sakula is a remote access tool (RAT) that first surfaced in 2012 and was used in intrusions throughout 2015.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Sakula uses single-byte XOR obfuscation to obfuscate many of its files.

T1059.003
Windows Command Shell

Sakula calls cmd.exe to run various DLL files via rundll32 and also to perform file cleanup. Sakula also has the capability to invoke a reverse shell.

T1070.004
File Deletion

Some Sakula samples use cmd.exe to delete temporary files.

T1071.001
Web Protocols

Sakula uses HTTP for C2.

T1105
Ingress Tool Transfer

Sakula has the capability to download files.

T1218.011
Rundll32

Sakula calls cmd.exe to run various DLL files via rundll32.

T1543.003
Windows Service

Some Sakula samples install themselves as services for persistence by calling WinExec with the net start argument.

T1547.001
Registry Run Keys / Startup Folder

Most Sakula samples maintain persistence by setting the Registry Run key SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ in the HKLM or HKCU hive, with the Registry value and file name varying by sample.

T1548.002
Bypass User Account Control

Sakula contains UAC bypass code for both 32- and 64-bit systems.

T1573.001
Symmetric Cryptography

Sakula encodes C2 traffic with single-byte XOR keys.

T1574.001
DLL

Sakula uses DLL side-loading, typically using a digitally signed sample of Kaspersky Anti-Virus (AV) 6.0 for Windows Workstations or McAfee's Outlook Scan About Box to load malicious DLL files.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Dell Sakula Open source
    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, July 30). Sakula Malware Family. Retrieved January 26, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.