MirageFox

S0280

Malware.View on attack.mitre.org

About this malware

MirageFox is a remote access tool used against Windows systems. It appears to be an upgraded version of a tool known as Mirage, which is a RAT believed to originate in 2012.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1033
System Owner/User Discovery

MirageFox can gather the username from the victim’s machine.

T1059.003
Windows Command Shell

MirageFox has the capability to execute commands using cmd.exe.

T1082
System Information Discovery

MirageFox can collect CPU and architecture information from the victim’s machine.

T1140
Deobfuscate/Decode Files or Information

MirageFox has a function for decrypting data containing C2 configuration information.

T1574.001
DLL

MirageFox is likely loaded via DLL hijacking into a legitimate McAfee binary.

Groups that use it1

Campaigns0

None recorded.

References1

  1. APT15 Intezer June 2018 Open source
    Rosenberg, J. (2018, June 14). MirageFox: APT15 Resurfaces With New Tools Based On Old Ones. Retrieved September 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.