ATT&CKSoftwareBlackEnergy

BlackEnergy

S0089

Malware.View on attack.mitre.org

About this malware

BlackEnergy is a malware toolkit that has been used by both criminal and APT actors. It dates back to at least 2007 and was originally designed to create botnets for use in conducting Distributed Denial of Service (DDoS) attacks, but its use has evolved to support various plug-ins. It is well known for being used during the confrontation between Georgia and Russia in 2008, as well as in targeting Ukrainian institutions. Variants include BlackEnergy 2 and BlackEnergy 3.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1008
Fallback Channels

BlackEnergy has the capability to communicate over a backup channel via plus.google.com.

T1016
System Network Configuration Discovery

BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe.

T1021.002
SMB/Windows Admin Shares

BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares.

T1046
Network Service Discovery

BlackEnergy has conducted port scans on a host.

T1047
Windows Management Instrumentation

A BlackEnergy 2 plug-in uses WMI to gather victim host details.

T1049
System Network Connections Discovery

BlackEnergy has gathered information about local network connections using netstat.

T1055.001
Dynamic-link Library Injection

BlackEnergy injects its DLL component into svchost.exe.

T1056.001
Keylogging

BlackEnergy has run a keylogger plug-in on a victim.

T1057
Process Discovery

BlackEnergy has gathered a process list by using Tasklist.exe.

T1070
Indicator Removal

BlackEnergy has removed the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevant strings in the user32.dll.mui of the system.

T1071.001
Web Protocols

BlackEnergy communicates with its C2 server over HTTP.

T1082
System Information Discovery

BlackEnergy has used Systeminfo to gather the OS version, as well as information on the system configuration, BIOS, the motherboard, and the processor.

T1083
File and Directory Discovery

BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types.

T1113
Screen Capture

BlackEnergy is capable of taking screenshots.

T1120
Peripheral Device Discovery

BlackEnergy can gather very specific information about attached USB devices, to include device instance ID and drive geometry.

View all 25 procedure examples

Groups that use it1

Campaigns1

References1

  1. F-Secure BlackEnergy 2014 Open source
    F-Secure Labs. (2014). BlackEnergy & Quedagh: The convergence of crimeware and APT attacks. Retrieved March 24, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.