XTunnel

S0117

Malware.View on attack.mitre.org

About this malware

XTunnel a VPN-like network proxy tool that can relay traffic between a C2 server and a victim. It was first seen in May 2013 and reportedly used by APT28 during the compromise of the Democratic National Committee.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1008
Fallback Channels

The C2 server used by XTunnel provides a port number to the victim to use as a fallback in case the connection closes on the currently used port.

T1027
Obfuscated Files or Information

A version of XTunnel introduced in July 2015 obfuscated the binary using opaque predicates and other techniques in a likely attempt to obfuscate it and bypass security products.

T1027.016
Junk Code Insertion

A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products.

T1046
Network Service Discovery

XTunnel is capable of probing the network for open ports.

T1059.003
Windows Command Shell

XTunnel has been used to execute remote commands.

T1090
Proxy

XTunnel relays traffic between a C2 server and a victim.

T1552.001
Credentials In Files

XTunnel is capable of accessing locally stored passwords on victims.

T1573.002
Asymmetric Cryptography

XTunnel uses SSL/TLS and RC4 to encrypt traffic.

Groups that use it1

Campaigns0

None recorded.

References3

  1. Crowdstrike DNC June 2016 Open source
    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.
  2. ESET Sednit Part 2 Open source
    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.
  3. Invincea XTunnel Open source
    Belcher, P.. (2016, July 28). Tunnel of Gov: DNC Hack and the Russian XTunnel. Retrieved August 3, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.