RATANKBA

S0241

Malware.View on attack.mitre.org

About this malware

RATANKBA is a remote controller tool used by Lazarus Group. RATANKBA has been used in attacks targeting financial institutions in Poland, Mexico, Uruguay, the United Kingdom, and Chile. It was also seen used against organizations related to telecommunications, management consulting, information technology, insurance, aviation, and education. RATANKBA has a graphical user interface to allow the attacker to issue jobs to perform on the infected machines.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1007
System Service Discovery

RATANKBA uses tasklist /svc to display running tasks.

T1012
Query Registry

RATANKBA uses the command reg query “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings”.

T1016
System Network Configuration Discovery

RATANKBA gathers the victim’s IP address via the ipconfig -all command.

T1018
Remote System Discovery

RATANKBA runs the net view /domain and net view commands.

T1033
System Owner/User Discovery

RATANKBA runs the whoami and query user commands.

T1047
Windows Management Instrumentation

RATANKBA uses WMI to perform process monitoring.

T1049
System Network Connections Discovery

RATANKBA uses netstat -ano to search for specific IP address ranges.

T1055.001
Dynamic-link Library Injection

RATANKBA performs a reflective DLL injection using a given pid.

T1057
Process Discovery

RATANKBA lists the system’s processes.

T1059.001
PowerShell

There is a variant of RATANKBA that uses a PowerShell script instead of the traditional PE form.

T1059.003
Windows Command Shell

RATANKBA uses cmd.exe to execute commands.

T1071.001
Web Protocols

RATANKBA uses HTTP/HTTPS for command and control communication.

T1082
System Information Discovery

RATANKBA gathers information about the OS architecture, OS name, and OS version/Service pack.

T1087.001
Local Account

RATANKBA uses the net user command.

T1105
Ingress Tool Transfer

RATANKBA uploads and downloads information.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Lazarus RATANKBA Open source
    Lei, C., et al. (2018, January 24). Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool, an Evolved RATANKBA, and More. Retrieved May 22, 2018.
  2. RATANKBA Open source
    Trend Micro. (2017, February 27). RATANKBA: Delving into Large-scale Watering Holes against Enterprises. Retrieved May 22, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.