Malware.View on attack.mitre.org
Matryoshka is a malware framework used by CopyKittens that consists of a dropper, loader, and RAT. It has multiple versions; v1 was seen in the wild from July 2016 until January 2017. v2 has fewer commands and other minor differences.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Matryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding. |
| T1053.005 Scheduled Task |
Matryoshka can establish persistence by adding a Scheduled Task named "Microsoft Boost Kernel Optimization". |
| T1055.001 Dynamic-link Library Injection |
Matryoshka uses reflective DLL injection to inject the malicious library and execute the RAT. |
| T1056.001 Keylogging |
Matryoshka is capable of keylogging. |
| T1059 Command and Scripting Interpreter |
Matryoshka is capable of providing Meterpreter shell access. |
| T1071.004 DNS |
Matryoshka uses DNS for C2. |
| T1113 Screen Capture |
Matryoshka is capable of performing screen captures. |
| T1218.011 Rundll32 |
Matryoshka uses rundll32.exe in a Registry Run key value for execution as part of its persistence mechanism. |
| T1547.001 Registry Run Keys / Startup Folder |
Matryoshka can establish persistence by adding Registry Run keys. |
| T1555 Credentials from Password Stores |
Matryoshka is capable of stealing Outlook passwords. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.