Malware.View on attack.mitre.org
BlackEnergy is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3.
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
BlackEnergy has the capability to communicate over a backup channel via plus.google.com. |
| T1016 System Network Configuration Discovery |
BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe. |
| T1021.002 SMB/Windows Admin Shares |
BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares. |
| T1046 Network Service Discovery |
BlackEnergy has conducted port scans on a host. |
| T1047 Windows Management Instrumentation |
A BlackEnergy 2 plug-in uses WMI to gather victim host details. |
| T1049 System Network Connections Discovery |
BlackEnergy has gathered information about local network connections using netstat. |
| T1055.001 Dynamic-link Library Injection |
BlackEnergy injects its DLL component into svchost.exe. |
| T1056.001 Keylogging |
BlackEnergy has run a keylogger plug-in on a victim. |
| T1057 Process Discovery |
BlackEnergy has gathered a process list by using Tasklist.exe. |
| T1070 Indicator Removal |
BlackEnergy has removed the watermark associated with enabling the |
| T1071.001 Web Protocols |
BlackEnergy communicates with its C2 server over HTTP. |
| T1082 System Information Discovery |
BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor. |
| T1083 File and Directory Discovery |
BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types. |
| T1113 Screen Capture |
BlackEnergy is capable of taking screenshots. |
| T1120 Peripheral Device Discovery |
BlackEnergy can gather very specific information about attached USB devices, to include device instance ID and drive geometry. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.