Orz

S0229

Malware.View on attack.mitre.org

About this malware

Orz is a custom JavaScript backdoor used by Leviathan. It was observed being used in 2014 as well as in August 2017 when it was dropped by Microsoft Publisher files.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1016
System Network Configuration Discovery

Orz can gather victim proxy information.

T1027
Obfuscated Files or Information

Some Orz strings are base64 encoded, such as the embedded DLL known as MockDll.

T1055.012
Process Hollowing

Some Orz versions have an embedded DLL known as MockDll that uses process hollowing and Regsvr32 to execute another payload.

T1057
Process Discovery

Orz can gather a process list from the victim.

T1059.003
Windows Command Shell

Orz can execute shell commands. Orz can execute commands with JavaScript.

T1070
Indicator Removal

Orz can overwrite Registry settings to reduce its visibility on the victim.

T1082
System Information Discovery

Orz can gather the victim OS version and whether it is 64 or 32 bit.

T1083
File and Directory Discovery

Orz can gather victim drive information.

T1102.002
Bidirectional Communication

Orz has used Technet and Pastebin web pages for command and control.

T1105
Ingress Tool Transfer

Orz can download files onto the victim.

T1112
Modify Registry

Orz can perform Registry operations.

T1218.010
Regsvr32

Some Orz versions have an embedded DLL known as MockDll that uses Process Hollowing and regsvr32 to execute another payload.

T1518
Software Discovery

Orz can gather the victim's Internet Explorer version.

Groups that use it1

Campaigns0

None recorded.

References2

  1. FireEye Periscope March 2018 Open source
    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.
  2. Proofpoint Leviathan Oct 2017 Open source
    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.