VERMIN

S0257

Malware.View on attack.mitre.org

About this malware

VERMIN is a remote access tool written in the Microsoft .NET framework. It is mostly composed of original code, but also has some open source code.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1016
System Network Configuration Discovery

VERMIN gathers the local IP address.

T1027.002
Software Packing

VERMIN is initially packed.

T1027.013
Encrypted/Encoded File

VERMIN is obfuscated using the obfuscation tool called ConfuserEx.

T1033
System Owner/User Discovery

VERMIN gathers the username from the victim’s machine.

T1056.001
Keylogging

VERMIN collects keystrokes from the victim machine.

T1057
Process Discovery

VERMIN can get a list of the processes and running tasks on the system.

T1070.004
File Deletion

VERMIN can delete files on the victim’s machine.

T1071.001
Web Protocols

VERMIN uses HTTP for C2 communications.

T1082
System Information Discovery

VERMIN collects the OS name, machine name, and architecture information.

T1105
Ingress Tool Transfer

VERMIN can download and upload files to the victim's machine.

T1113
Screen Capture

VERMIN can perform screen captures of the victim’s machine.

T1115
Clipboard Data

VERMIN collects data stored in the clipboard.

T1119
Automated Collection

VERMIN saves each collected file with the automatically generated format {0:dd-MM-yyyy}.txt .

T1123
Audio Capture

VERMIN can perform audio capture.

T1140
Deobfuscate/Decode Files or Information

VERMIN decrypts code, strings, and commands to use once it's on the victim's machine.

View all 17 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Unit 42 VERMIN Jan 2018 Open source
    Lancaster, T., Cortes, J. (2018, January 29). VERMIN: Quasar RAT and Custom Malware Used In Ukraine. Retrieved July 5, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.