OceanSalt

S0346

Malware.View on attack.mitre.org

About this malware

OceanSalt is a Trojan that was used in a campaign targeting victims in South Korea, United States, and Canada. OceanSalt shares code similarity with SpyNote RAT, which has been linked to APT1.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1016
System Network Configuration Discovery

OceanSalt can collect the victim’s IP address.

T1057
Process Discovery

OceanSalt can collect the name and ID for every process running on the system.

T1059.003
Windows Command Shell

OceanSalt can create a reverse shell on the infected endpoint using cmd.exe. OceanSalt has been executed via malicious macros.

T1070.004
File Deletion

OceanSalt can delete files from the system.

T1082
System Information Discovery

OceanSalt can collect the computer name from the system.

T1083
File and Directory Discovery

OceanSalt can extract drive information from the endpoint and search files on the system.

T1132.002
Non-Standard Encoding

OceanSalt can encode data with a NOT operation before sending the data to the control server.

T1566.001
Spearphishing Attachment

OceanSalt has been delivered via spearphishing emails with Microsoft Office attachments.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. McAfee Oceansalt Oct 2018 Open source
    Sherstobitoff, R., Malhotra, A. (2018, October 18). ‘Operation Oceansalt’ Attacks South Korea, U.S., and Canada With Source Code From Chinese Hacker Group. Retrieved November 30, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.