Kazuar

S0265

Malware.View on attack.mitre.org

About this malware

Kazuar is a fully featured, multi-platform backdoor Trojan written using the Microsoft .NET framework.

Techniques used31

Procedure examples31

TechniqueProcedure example
T1005
Data from Local System

Kazuar uploads files from a specified directory to the C2 server.

T1008
Fallback Channels

Kazuar can accept multiple URLs for C2 servers.

T1010
Application Window Discovery

Kazuar gathers information about opened windows.

T1016
System Network Configuration Discovery

Kazuar gathers information about network adapters.

T1027
Obfuscated Files or Information

Kazuar is obfuscated using the open source ConfuserEx protector. Kazuar also obfuscates the name of created files/folders/mutexes and encrypts debug messages written to log files using the Rijndael cipher.

T1029
Scheduled Transfer

Kazuar can sleep for a specific time and be set to communicate at specific intervals.

T1033
System Owner/User Discovery

Kazuar gathers information on users.

T1047
Windows Management Instrumentation

Kazuar obtains a list of running processes through WMI querying.

T1055.001
Dynamic-link Library Injection

If running in a Windows environment, Kazuar saves a DLL to disk that is injected into the explorer.exe process to execute the payload. Kazuar can also be configured to inject and execute within specific processes.

T1057
Process Discovery

Kazuar obtains a list of running processes through WMI querying and the ps command.

T1059.003
Windows Command Shell

Kazuar uses cmd.exe to execute commands on the victim’s machine.

T1059.004
Unix Shell

Kazuar uses /bin/bash to execute commands on the victim’s machine.

T1069.001
Local Groups

Kazuar gathers information about local groups and members.

T1070.004
File Deletion

Kazuar can delete files.

T1071.001
Web Protocols

Kazuar uses HTTP and HTTPS to communicate with the C2 server. Kazuar can also act as a webserver and listen for inbound HTTP requests through an exposed API.

View all 31 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit 42 Kazuar May 2017 Open source
    Levene, B, et al. (2017, May 03). Kazuar: Multiplatform Espionage Backdoor with API Access. Retrieved July 17, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.