ATT&CKSoftwareTrojan.Karagany

Trojan.Karagany

S0094

Malware.View on attack.mitre.org

About this malware

Trojan.Karagany is a modular remote access tool used for recon and linked to Dragonfly. The source code for Trojan.Karagany originated from Dream Loader malware which was leaked in 2010 and sold on underground forums.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1003
OS Credential Dumping

Trojan.Karagany can dump passwords and save them into \ProgramData\Mail\MailAg\pwds.txt.

T1010
Application Window Discovery

Trojan.Karagany can monitor the titles of open windows to identify specific keywords.

T1016
System Network Configuration Discovery

Trojan.Karagany can gather information on the network configuration of a compromised host.

T1027
Obfuscated Files or Information

Trojan.Karagany can base64 encode and AES-128-CBC encrypt data prior to transmission.

T1027.002
Software Packing

Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer.

T1033
System Owner/User Discovery

Trojan.Karagany can gather information about the user on a compromised host.

T1049
System Network Connections Discovery

Trojan.Karagany can use netstat to collect a list of network connections.

T1055.003
Thread Execution Hijacking

Trojan.Karagany can inject a suspended thread of its own process into a new process and initiate via the ResumeThread API.

T1056.001
Keylogging

Trojan.Karagany can capture keystrokes on a compromised host.

T1057
Process Discovery

Trojan.Karagany can use Tasklist to collect a list of running tasks.

T1059.003
Windows Command Shell

Trojan.Karagany can perform reconnaissance commands on a victim machine via a cmd.exe process.

T1070.004
File Deletion

Trojan.Karagany has used plugins with a self-delete capability.

T1071.001
Web Protocols

Trojan.Karagany can communicate with C2 via HTTP POST requests.

T1074.001
Local Data Staging

Trojan.Karagany can create directories to store plugin output and stage data for exfiltration.

T1082
System Information Discovery

Trojan.Karagany can capture information regarding the victim's OS, security, and hardware configuration.

View all 22 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. Dragos DYMALLOY Open source
    Dragos. (n.d.). DYMALLOY. Retrieved August 20, 2020.
  2. Secureworks Karagany July 2019 Open source
    Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.
  3. Symantec Dragonfly Open source
    Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.