MURKYTOP

S0233

Malware.View on attack.mitre.org

About this malware

MURKYTOP is a reconnaissance tool used by Leviathan.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1018
Remote System Discovery

MURKYTOP has the capability to identify remote hosts on connected networks.

T1046
Network Service Discovery

MURKYTOP has the capability to scan for open ports on hosts in a connected network.

T1053.002
At

MURKYTOP has the capability to schedule remote AT jobs.

T1059.003
Windows Command Shell

MURKYTOP uses the command-line interface.

T1069
Permission Groups Discovery

MURKYTOP has the capability to retrieve information about groups.

T1070.004
File Deletion

MURKYTOP has the capability to delete local files.

T1082
System Information Discovery

MURKYTOP has the capability to retrieve information about the OS.

T1087.001
Local Account

MURKYTOP has the capability to retrieve information about users on remote hosts.

T1135
Network Share Discovery

MURKYTOP has the capability to retrieve information about shares on remote hosts.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye Periscope March 2018 Open source
    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.