ATT&CKSoftwareUnknown Logger

Unknown Logger

S0130

Malware.View on attack.mitre.org

About this malware

Unknown Logger is a publicly released, free backdoor. Version 1.5 of the backdoor has been used by the actors responsible for the MONSOON campaign.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1016
System Network Configuration Discovery

Unknown Logger can obtain information about the victim's IP address.

T1033
System Owner/User Discovery

Unknown Logger can obtain information about the victim usernames.

T1056.001
Keylogging

Unknown Logger is capable of recording keystrokes.

T1082
System Information Discovery

Unknown Logger can obtain information about the victim computer name, physical memory, country, and date.

T1091
Replication Through Removable Media

Unknown Logger is capable of spreading to USB devices.

T1105
Ingress Tool Transfer

Unknown Logger is capable of downloading remote files.

T1555.003
Credentials from Web Browsers

Unknown Logger is capable of stealing usernames and passwords from browsers on the victim machine.

T1685
Disable or Modify Tools

Unknown Logger has functionality to disable security tools, including Kaspersky, BitDefender, and MalwareBytes.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Forcepoint Monsoon Open source
    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.