CORESHELL

S0137

Malware.View on attack.mitre.org

About this malware

CORESHELL is a downloader used by APT28. The older versions of this malware are known as SOURFACE and newer versions as CORESHELL.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027
Obfuscated Files or Information

CORESHELL obfuscates strings using a custom stream cipher.

T1027.016
Junk Code Insertion

CORESHELL contains unused machine instructions in a likely attempt to hinder analysis.

T1071.001
Web Protocols

CORESHELL can communicate over HTTP for C2.

T1071.003
Mail Protocols

CORESHELL can communicate over SMTP and POP3 for C2.

T1082
System Information Discovery

CORESHELL collects hostname and OS version data from the victim and sends the information to its C2 server.

T1105
Ingress Tool Transfer

CORESHELL downloads another dropper from its C2 server.

T1132.001
Standard Encoding

CORESHELL C2 messages are Base64-encoded.

T1218.011
Rundll32

CORESHELL is installed via execution of rundll32 with an export named "init" or "InitW."

T1547.001
Registry Run Keys / Startup Folder

CORESHELL has established persistence by creating autostart extensibility point (ASEP) Registry entries in the Run key and other Registry keys, as well as by creating shortcuts in the Internet Explorer Quick Start folder.

T1573.001
Symmetric Cryptography

CORESHELL C2 messages are encrypted with custom stream ciphers using six-byte or eight-byte keys.

T1680
Local Storage Discovery

CORESHELL collects the volume serial number from the victim and sends the information to its C2 server.

Groups that use it1

Campaigns0

None recorded.

References2

  1. FireEye APT28 Open source
    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.
  2. FireEye APT28 January 2017 Open source
    FireEye iSIGHT Intelligence. (2017, January 11). APT28: At the Center of the Storm. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.