ATT&CKSoftwarePUNCHBUGGY

PUNCHBUGGY

S0196

Malware.View on attack.mitre.org

About this malware

PUNCHBUGGY is a backdoor malware used by FIN8 that has been observed targeting POS networks in the hospitality industry.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1027
Obfuscated Files or Information

PUNCHBUGGY has hashed most its code's functions and encrypted payloads with base64 and XOR.

T1036.005
Match Legitimate Resource Name or Location

PUNCHBUGGY mimics filenames from %SYSTEM%\System32 to hide DLLs in %WINDIR% and/or %TEMP%.

T1059.001
PowerShell

PUNCHBUGGY has used PowerShell scripts.

T1059.006
Python

PUNCHBUGGY has used python scripts.

T1070.004
File Deletion

PUNCHBUGGY can delete files written to disk.

T1071.001
Web Protocols

PUNCHBUGGY enables remote interaction and can obtain additional code over HTTPS GET and POST requests.

T1074.001
Local Data Staging

PUNCHBUGGY has saved information to a random temp file before exfil.

T1082
System Information Discovery

PUNCHBUGGY can gather system information such as computer names.

T1087.001
Local Account

PUNCHBUGGY can gather user names.

T1105
Ingress Tool Transfer

PUNCHBUGGY can download additional files and payloads to compromised hosts.

T1129
Shared Modules

PUNCHBUGGY can load a DLL using the LoadLibrary API.

T1140
Deobfuscate/Decode Files or Information

PUNCHBUGGY has used PowerShell to decode base64-encoded assembly.

T1218.011
Rundll32

PUNCHBUGGY can load a DLL using Rundll32.

T1518.001
Security Software Discovery

PUNCHBUGGY can gather AVs registered in the system.

T1546.009
AppCert DLLs

PUNCHBUGGY can establish using a AppCertDLLs Registry key.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. FireEye Fin8 May 2016 Open source
    Kizhakkinan, D., et al. (2016, May 11). Threat Actor Leverages Windows Zero-day Exploit in Payment Card Data Attacks. Retrieved February 12, 2018.
  2. FireEye Know Your Enemy FIN8 Aug 2016 Open source
    Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.
  3. Morphisec ShellTea June 2019 Open source
    Gorelik, M.. (2019, June 10). SECURITY ALERT: FIN8 IS BACK IN BUSINESS, TARGETING THE HOSPITALITY INDUSTRY. Retrieved June 13, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.