ATT&CKSoftwareRunningRAT

RunningRAT

S0253

Malware.View on attack.mitre.org

About this malware

RunningRAT is a remote access tool that appeared in operations surrounding the 2018 Pyeongchang Winter Olympics along with Gold Dragon and Brave Prince.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1056.001
Keylogging

RunningRAT captures keystrokes and sends them back to the C2 server.

T1059.003
Windows Command Shell

RunningRAT uses a batch file to kill a security program task and then attempts to remove itself.

T1070.004
File Deletion

RunningRAT contains code to delete files from the victim’s machine.

T1082
System Information Discovery

RunningRAT gathers the OS version and processor information.

T1115
Clipboard Data

RunningRAT contains code to open and copy data from the clipboard.

T1547.001
Registry Run Keys / Startup Folder

RunningRAT adds itself to the Registry key Software\Microsoft\Windows\CurrentVersion\Run to establish persistence upon reboot.

T1560
Archive Collected Data

RunningRAT contains code to compress files.

T1680
Local Storage Discovery

RunningRAT gathers logical drives information and volume information.

T1685
Disable or Modify Tools

RunningRAT kills antimalware running process.

T1685.005
Clear Windows Event Logs

RunningRAT contains code to clear event logs.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. McAfee Gold Dragon Open source
    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.