Malware.View on attack.mitre.org
Trojan.Karagany is a modular remote access tool used for recon and linked to Dragonfly. The source code for Trojan.Karagany originated from Dream Loader malware which was leaked in 2010 and sold on underground forums.
| Technique | Procedure example |
|---|---|
| T1003 OS Credential Dumping |
Trojan.Karagany can dump passwords and save them into |
| T1010 Application Window Discovery |
Trojan.Karagany can monitor the titles of open windows to identify specific keywords. |
| T1016 System Network Configuration Discovery |
Trojan.Karagany can gather information on the network configuration of a compromised host. |
| T1027 Obfuscated Files or Information |
Trojan.Karagany can base64 encode and AES-128-CBC encrypt data prior to transmission. |
| T1027.002 Software Packing |
Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer. |
| T1033 System Owner/User Discovery |
Trojan.Karagany can gather information about the user on a compromised host. |
| T1049 System Network Connections Discovery |
Trojan.Karagany can use netstat to collect a list of network connections. |
| T1055.003 Thread Execution Hijacking |
Trojan.Karagany can inject a suspended thread of its own process into a new process and initiate via the |
| T1056.001 Keylogging |
Trojan.Karagany can capture keystrokes on a compromised host. |
| T1057 Process Discovery |
Trojan.Karagany can use Tasklist to collect a list of running tasks. |
| T1059.003 Windows Command Shell |
Trojan.Karagany can perform reconnaissance commands on a victim machine via a cmd.exe process. |
| T1070.004 File Deletion |
Trojan.Karagany has used plugins with a self-delete capability. |
| T1071.001 Web Protocols |
Trojan.Karagany can communicate with C2 via HTTP POST requests. |
| T1074.001 Local Data Staging |
Trojan.Karagany can create directories to store plugin output and stage data for exfiltration. |
| T1082 System Information Discovery |
Trojan.Karagany can capture information regarding the victim's OS, security, and hardware configuration. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.