Volgmer

S0180

Malware.View on attack.mitre.org

About this malware

Volgmer is a backdoor Trojan designed to provide covert access to a compromised system. It has been used since at least 2013 to target the government, financial, automotive, and media industries. Its primary delivery mechanism is suspected to be spearphishing.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1007
System Service Discovery

Volgmer queries the system to identify existing services.

T1012
Query Registry

Volgmer checks the system for certain Registry keys.

T1016
System Network Configuration Discovery

Volgmer can gather the IP address from the victim's machine.

T1027.011
Fileless Storage

Volgmer stores an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1027.013
Encrypted/Encoded File

A Volgmer variant is encoded using a simple XOR cipher.

T1036.004
Masquerade Task or Service

Some Volgmer variants add new services with display names generated by a list of hard-coded strings such as Application, Background, Security, and Windows, presumably as a way to masquerade as a legitimate service.

T1049
System Network Connections Discovery

Volgmer can gather information about TCP connection state.

T1057
Process Discovery

Volgmer can gather a list of processes.

T1059.003
Windows Command Shell

Volgmer can execute commands on the victim's machine.

T1070.004
File Deletion

Volgmer can delete files and itself after infection to avoid analysis.

T1082
System Information Discovery

Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine.

T1083
File and Directory Discovery

Volgmer can list directories on a victim.

T1105
Ingress Tool Transfer

Volgmer can download remote files and additional payloads to the victim's machine.

T1106
Native API

Volgmer executes payloads using the Windows API call CreateProcessW().

T1112
Modify Registry

Volgmer modifies the Registry to store an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. US-CERT Volgmer Nov 2017 Open source
    US-CERT. (2017, November 22). Alert (TA17-318B): HIDDEN COBRA – North Korean Trojan: Volgmer. Retrieved December 7, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.