Reaver

S0172

Malware.View on attack.mitre.org

About this malware

Reaver is a malware family that has been in the wild since at least late 2016. Reporting indicates victims have primarily been associated with the "Five Poisons," which are movements the Chinese government considers dangerous. The type of malware is rare due to its final payload being in the form of Control Panel items.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1012
Query Registry

Reaver queries the Registry to determine the correct Startup path to use for persistence.

T1016
System Network Configuration Discovery

Reaver collects the victim's IP address.

T1027.013
Encrypted/Encoded File

Reaver encrypts some of its files with XOR.

T1033
System Owner/User Discovery

Reaver collects the victim's username.

T1070.004
File Deletion

Reaver deletes the original dropped file from the victim.

T1071.001
Web Protocols

Some Reaver variants use HTTP for C2.

T1082
System Information Discovery

Reaver collects system information from the victim, including CPU speed, computer name, ANSI code page, OEM code page identifier for the OS, Microsoft Windows version, and memory information.

T1095
Non-Application Layer Protocol

Some Reaver variants use raw TCP for C2.

T1218.002
Control Panel

Reaver drops and executes a malicious CPL file as its payload.

T1543.003
Windows Service

Reaver installs itself as a new service.

T1547.001
Registry Run Keys / Startup Folder

Reaver creates a shortcut file and saves it in a Startup folder to establish persistence.

T1547.009
Shortcut Modification

Reaver creates a shortcut file and saves it in a Startup folder to establish persistence.

T1560.003
Archive via Custom Method

Reaver encrypts collected data with an incremental XOR key prior to exfiltration.

T1680
Local Storage Discovery

Reaver collects volume serial number from the victim.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Palo Alto Reaver Nov 2017 Open source
    Grunzweig, J. and Miller-Osborn, J. (2017, November 10). New Malware with Ties to SunOrcal Discovered. Retrieved November 16, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.