ATT&CKSoftwareNDiskMonitor

NDiskMonitor

S0272

Malware.View on attack.mitre.org

About this malware

NDiskMonitor is a custom backdoor written in .NET that appears to be unique to Patchwork.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1033
System Owner/User Discovery

NDiskMonitor obtains the victim username and encrypts the information to send over its C2 channel.

T1082
System Information Discovery

NDiskMonitor obtains the victim computer name and encrypts the information to send over its C2 channel.

T1083
File and Directory Discovery

NDiskMonitor can obtain a list of all files and directories as well as logical drives.

T1105
Ingress Tool Transfer

NDiskMonitor can download and execute a file from given URL.

T1573.001
Symmetric Cryptography

NDiskMonitor uses AES to encrypt certain information sent over its C2 channel.

Groups that use it1

Campaigns0

None recorded.

References1

  1. TrendMicro Patchwork Dec 2017 Open source
    Lunghi, D., et al. (2017, December). Untangling the Patchwork Cyberespionage Group. Retrieved July 10, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.