UBoatRAT

S0333

Malware.View on attack.mitre.org

About this malware

UBoatRAT is a remote access tool that was identified in May 2017.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1057
Process Discovery

UBoatRAT can list running processes on the system.

T1059.003
Windows Command Shell

UBoatRAT can start a command shell.

T1071.001
Web Protocols

UBoatRAT has used HTTP for C2 communications.

T1102.002
Bidirectional Communication

UBoatRAT has used GitHub and a public blog service in Hong Kong for C2 communications.

T1105
Ingress Tool Transfer

UBoatRAT can upload and download files to the victim’s machine.

T1197
BITS Jobs

UBoatRAT takes advantage of the /SetNotifyCmdLine option in BITSAdmin to ensure it stays running on a system to maintain persistence.

T1497.001
System Checks

UBoatRAT checks for virtualization software such as VMWare, VirtualBox, or QEmu on the compromised machine.

T1573.001
Symmetric Cryptography

UBoatRAT encrypts instructions in its C2 network payloads using a simple XOR cipher.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. PaloAlto UBoatRAT Nov 2017 Open source
    Hayashi, K. (2017, November 28). UBoatRAT Navigates East Asia. Retrieved January 12, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.