WEBC2

S0109

Malware.View on attack.mitre.org

About this malware

WEBC2 is a family of backdoor malware used by APT1 as early as July 2006. WEBC2 backdoors are designed to retrieve a webpage, with commands hidden in HTML comments or special tags, from a predetermined C2 server.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1059.003
Windows Command Shell

WEBC2 can open an interactive command shell.

T1105
Ingress Tool Transfer

WEBC2 can download and execute a file.

T1574.001
DLL

Variants of WEBC2 achieve persistence by using DLL search order hijacking, usually by copying the DLL file to %SYSTEMROOT% (C:\WINDOWS\ntshrui.dll).

Groups that use it1

Campaigns0

None recorded.

References2

  1. Mandiant APT1 Open source
    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
  2. Mandiant APT1 Appendix Open source
    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.