PLAINTEE

S0254

Malware.View on attack.mitre.org

About this malware

PLAINTEE is a malware sample that has been used by Rancor in targeted attacks in Singapore and Cambodia.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1016
System Network Configuration Discovery

PLAINTEE uses the ipconfig /all command to gather the victim’s IP address.

T1057
Process Discovery

PLAINTEE performs the tasklist command to list running processes.

T1059.003
Windows Command Shell

PLAINTEE uses cmd.exe to execute commands on the victim’s machine.

T1082
System Information Discovery

PLAINTEE collects general system enumeration data about the infected machine and checks the OS version.

T1105
Ingress Tool Transfer

PLAINTEE has downloaded and executed additional plugins.

T1112
Modify Registry

PLAINTEE uses reg add to add a Registry Run key for persistence.

T1547.001
Registry Run Keys / Startup Folder

PLAINTEE gains persistence by adding the Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce.

T1548.002
Bypass User Account Control

An older variant of PLAINTEE performs UAC bypass.

T1573.001
Symmetric Cryptography

PLAINTEE encodes C2 beacons using XOR.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Rancor Unit42 June 2018 Open source
    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.