ATT&CKSoftwareInnaputRAT

InnaputRAT

S0259

Malware.View on attack.mitre.org

About this malware

InnaputRAT is a remote access tool that can exfiltrate files from a victim’s machine. InnaputRAT has been seen out in the wild since 2016.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027
Obfuscated Files or Information

InnaputRAT uses an 8-byte XOR key to obfuscate API names and other strings contained in the payload.

T1036.004
Masquerade Task or Service

InnaputRAT variants have attempted to appear legitimate by adding a new service named OfficeUpdateService.

T1036.005
Match Legitimate Resource Name or Location

InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe.

T1059.003
Windows Command Shell

InnaputRAT launches a shell to execute commands on the victim’s machine.

T1070.004
File Deletion

InnaputRAT has a command to delete files.

T1082
System Information Discovery

InnaputRAT gathers system information.

T1083
File and Directory Discovery

InnaputRAT enumerates directories and obtains file attributes on a system.

T1106
Native API

InnaputRAT uses the API call ShellExecuteW for execution.

T1543.003
Windows Service

Some InnaputRAT variants create a new Windows service to establish persistence.

T1547.001
Registry Run Keys / Startup Folder

Some InnaputRAT variants establish persistence by modifying the Registry key HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Run:%appdata%\NeutralApp\NeutralApp.exe.

T1680
Local Storage Discovery

InnaputRAT gathers volume drive information.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. ASERT InnaputRAT April 2018 Open source
    ASERT Team. (2018, April 04). Innaput Actors Utilize Remote Access Trojan Since 2016, Presumably Targeting Victim Files. Retrieved July 9, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.