Malware.View on attack.mitre.org
InnaputRAT is a remote access tool that can exfiltrate files from a victim’s machine. InnaputRAT has been seen out in the wild since 2016.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
InnaputRAT uses an 8-byte XOR key to obfuscate API names and other strings contained in the payload. |
| T1036.004 Masquerade Task or Service |
InnaputRAT variants have attempted to appear legitimate by adding a new service named OfficeUpdateService. |
| T1036.005 Match Legitimate Resource Name or Location |
InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe. |
| T1059.003 Windows Command Shell |
InnaputRAT launches a shell to execute commands on the victim’s machine. |
| T1070.004 File Deletion |
InnaputRAT has a command to delete files. |
| T1082 System Information Discovery |
InnaputRAT gathers system information. |
| T1083 File and Directory Discovery |
InnaputRAT enumerates directories and obtains file attributes on a system. |
| T1106 Native API |
InnaputRAT uses the API call ShellExecuteW for execution. |
| T1543.003 Windows Service |
Some InnaputRAT variants create a new Windows service to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
Some InnaputRAT variants establish persistence by modifying the Registry key |
| T1680 Local Storage Discovery |
InnaputRAT gathers volume drive information. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.