HARDRAIN

S0246

Malware.View on attack.mitre.org

About this malware

HARDRAIN is a Trojan malware variant reportedly used by the North Korean government.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

HARDRAIN uses FakeTLS to communicate with its C2 server.

T1059.003
Windows Command Shell

HARDRAIN uses cmd.exe to execute netshcommands.

T1090
Proxy

HARDRAIN uses the command cmd.exe /c netsh firewall add portopening TCP 443 "adp" and makes the victim machine function as a proxy server.

T1571
Non-Standard Port

HARDRAIN binds and listens on port 443 with a FakeTLS method.

T1686.003
Windows Host Firewall

HARDRAIN opens the Windows Firewall to modify incoming connections.

Groups that use it1

Campaigns0

None recorded.

References1

  1. US-CERT HARDRAIN March 2018 Open source
    US-CERT. (2018, February 05). Malware Analysis Report (MAR) - 10135536-F. Retrieved June 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.