Downdelph

S0134

Malware.View on attack.mitre.org

About this malware

Downdelph is a first-stage downloader written in Delphi that has been used by APT28 in rare instances between 2013 and 2015.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1001.001
Junk Data

Downdelph inserts pseudo-random characters between each original character during encoding of C2 network requests, making it difficult to write signatures on them.

T1105
Ingress Tool Transfer

After downloading its main config file, Downdelph downloads multiple payloads from C2 servers.

T1548.002
Bypass User Account Control

Downdelph bypasses UAC to escalate privileges by using a custom “RedirectEXE” shim database.

T1573.001
Symmetric Cryptography

Downdelph uses RC4 to encrypt C2 responses.

T1574.001
DLL

Downdelph uses search order hijacking of the Windows executable sysprep.exe to escalate privileges.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET Sednit Part 3 Open source
    ESET. (2016, October). En Route with Sednit - Part 3: A Mysterious Downloader. Retrieved November 21, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.