KARAE

S0215

Malware.View on attack.mitre.org

About this malware

KARAE is a backdoor typically used by APT37 as first-stage malware.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1082
System Information Discovery

KARAE can collect system information.

T1102.002
Bidirectional Communication

KARAE can use public cloud-based storage providers for command and control.

T1105
Ingress Tool Transfer

KARAE can upload and download files, including second-stage malware.

T1189
Drive-by Compromise

KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT37 Feb 2018 Open source
    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.