ATT&CKSoftwareExaramel for Windows

Exaramel for Windows

S0343

Malware.View on attack.mitre.org

About this malware

Exaramel for Windows is a backdoor used for targeting Windows systems. The Linux version is tracked separately under Exaramel for Linux.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.011
Fileless Storage

Exaramel for Windows stores the backdoor's configuration in the Registry in XML format.

T1036.004
Masquerade Task or Service

The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV” in an apparent attempt to masquerade as a legitimate service.

T1059.003
Windows Command Shell

Exaramel for Windows has a command to launch a remote shell and executes commands on the victim’s machine.

T1059.005
Visual Basic

Exaramel for Windows has a command to execute VBS scripts on the victim’s machine.

T1074.001
Local Data Staging

Exaramel for Windows specifies a path to store files scheduled for exfiltration.

T1112
Modify Registry

Exaramel for Windows adds the configuration to the Registry in XML format.

T1543.003
Windows Service

The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV.”

T1560
Archive Collected Data

Exaramel for Windows automatically encrypts files before sending them to the C2 server.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET TeleBots Oct 2018 Open source
    Cherepanov, A., Lipovsky, R. (2018, October 11). New TeleBots backdoor: First evidence linking Industroyer to NotPetya. Retrieved November 27, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.