POSHSPY

S0150

Malware.View on attack.mitre.org

About this malware

POSHSPY is a backdoor that has been used by APT29 since at least 2015. It appears to be used as a secondary backdoor used if the actors lost access to their primary backdoors.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027
Obfuscated Files or Information

POSHSPY appends a file signature header (randomly selected from six file types) to encrypted data prior to upload or download.

T1030
Data Transfer Size Limits

POSHSPY uploads data in 2048-byte chunks.

T1059.001
PowerShell

POSHSPY uses PowerShell to execute various commands, one to execute its payload.

T1070.006
Timestomp

POSHSPY modifies timestamps of all downloaded executables to match a randomly selected file created prior to 2013.

T1105
Ingress Tool Transfer

POSHSPY downloads and executes additional PowerShell code and Windows binaries.

T1546.003
Windows Management Instrumentation Event Subscription

POSHSPY uses a WMI event subscription to establish persistence.

T1568.002
Domain Generation Algorithms

POSHSPY uses a DGA to derive command and control URLs from a word list.

T1573.002
Asymmetric Cryptography

POSHSPY encrypts C2 traffic with AES and RSA.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye POSHSPY April 2017 Open source
    Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.