Malware.View on attack.mitre.org
BADCALL is a Trojan malware variant used by the group Lazarus Group.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
BADCALL uses a FakeTLS method during C2. |
| T1016 System Network Configuration Discovery |
BADCALL collects the network adapter information. |
| T1082 System Information Discovery |
BADCALL collects the computer name and host name on the compromised system. |
| T1090 Proxy |
BADCALL functions as a proxy server between the victim and C2 server. |
| T1112 Modify Registry |
BADCALL modifies the firewall Registry key |
| T1571 Non-Standard Port |
BADCALL communicates on ports 443 and 8000 with a FakeTLS method. |
| T1573.001 Symmetric Cryptography |
BADCALL encrypts C2 traffic using an XOR/ADD cipher. |
| T1686.003 Windows Host Firewall |
BADCALL disables the Windows firewall before binding to a port. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.