Octopus

S0340

Malware.View on attack.mitre.org

About this malware

Octopus is a Windows Trojan written in the Delphi programming language that has been used by Nomadic Octopus to target government organizations in Central Asia since at least 2014.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1005
Data from Local System

Octopus can exfiltrate files from the system using a documents collector tool.

T1016
System Network Configuration Discovery

Octopus can collect the host IP address from the victim’s machine.

T1033
System Owner/User Discovery

Octopus can collect the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location

Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger.

T1041
Exfiltration Over C2 Channel

Octopus has uploaded stolen files and data from a victim's machine over its C2 channel.

T1047
Windows Management Instrumentation

Octopus has used wmic.exe for local discovery information.

T1071.001
Web Protocols

Octopus has used HTTP GET and POST requests for C2 communications.

T1074.001
Local Data Staging

Octopus has stored collected information in the Application Data directory on a compromised host.

T1082
System Information Discovery

Octopus can collect the computer name, OS version, and OS architecture information.

T1083
File and Directory Discovery

Octopus can collect information on the Windows directory and searches for compressed RAR files on the host.

T1105
Ingress Tool Transfer

Octopus can download additional files and tools onto the victim’s machine.

T1113
Screen Capture

Octopus can capture screenshots of the victims’ machine.

T1132.001
Standard Encoding

Octopus has encoded C2 communications in Base64.

T1204.002
Malicious File

Octopus has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1547.001
Registry Run Keys / Startup Folder

Octopus achieved persistence by placing a malicious executable in the startup directory and has added the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to the Registry.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. ESET Nomadic Octopus 2018 Open source
    Cherepanov, A. (2018, October 4). Nomadic Octopus Cyber espionage in Central Asia. Retrieved October 13, 2021.
  2. Securelist Octopus Oct 2018 Open source
    Kaspersky Lab's Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018.
  3. Security Affairs DustSquad Oct 2018 Open source
    Paganini, P. (2018, October 16). Russia-linked APT group DustSquad targets diplomatic entities in Central Asia. Retrieved August 24, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.