Malware.View on attack.mitre.org
RATANKBA is a remote controller tool used by Lazarus Group. RATANKBA has been used in attacks targeting financial institutions in Poland, Mexico, Uruguay, the United Kingdom, and Chile. It was also seen used against organizations related to telecommunications, management consulting, information technology, insurance, aviation, and education. RATANKBA has a graphical user interface to allow the attacker to issue jobs to perform on the infected machines.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
RATANKBA uses |
| T1012 Query Registry |
RATANKBA uses the command |
| T1016 System Network Configuration Discovery |
RATANKBA gathers the victim’s IP address via the |
| T1018 Remote System Discovery |
RATANKBA runs the |
| T1033 System Owner/User Discovery |
RATANKBA runs the |
| T1047 Windows Management Instrumentation |
RATANKBA uses WMI to perform process monitoring. |
| T1049 System Network Connections Discovery |
RATANKBA uses |
| T1055.001 Dynamic-link Library Injection |
RATANKBA performs a reflective DLL injection using a given pid. |
| T1057 Process Discovery |
RATANKBA lists the system’s processes. |
| T1059.001 PowerShell |
There is a variant of RATANKBA that uses a PowerShell script instead of the traditional PE form. |
| T1059.003 Windows Command Shell |
RATANKBA uses cmd.exe to execute commands. |
| T1071.001 Web Protocols |
RATANKBA uses HTTP/HTTPS for command and control communication. |
| T1082 System Information Discovery |
RATANKBA gathers information about the OS architecture, OS name, and OS version/Service pack. |
| T1087.001 Local Account |
RATANKBA uses the |
| T1105 Ingress Tool Transfer |
RATANKBA uploads and downloads information. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.