Wingbird

S0176

Malware.View on attack.mitre.org

About this malware

Wingbird is a backdoor that appears to be a version of commercial software FinFisher. It is reportedly used to attack individual computers instead of networks. It was used by NEODYMIUM in a May 2016 campaign.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1055
Process Injection

Wingbird performs multiple process injections to hijack system processes and execute malicious code.

T1068
Exploitation for Privilege Escalation

Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges.

T1070.004
File Deletion

Wingbird deletes its payload along with the payload's parent process after it finishes copying files.

T1082
System Information Discovery

Wingbird checks the victim OS version after executing to determine where to drop files based on whether the victim is 32-bit or 64-bit.

T1518.001
Security Software Discovery

Wingbird checks for the presence of Bitdefender security software.

T1543.003
Windows Service

Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file.

T1547.008
LSASS Driver

Wingbird drops a malicious file (sspisrv.dll) alongside a copy of lsass.exe, which is used to register a service that loads sspisrv.dll as a driver. The payload of the malicious driver (located in its entry-point function) is executed when loaded by lsass.exe before the spoofed service becomes unstable and crashes.

T1569.002
Service Execution

Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file.

T1574.001
DLL

Wingbird side loads a malicious file, sspisrv.dll, in part of a spoofed lssas.exe service.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Microsoft NEODYMIUM Dec 2016 Open source
    Microsoft. (2016, December 14). Twin zero-day attacks: PROMETHIUM and NEODYMIUM target individuals in Europe. Retrieved November 27, 2017.
  2. Microsoft SIR Vol 21 Open source
    Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.