zwShell

S0350

Malware.View on attack.mitre.org

About this malware

zwShell is a remote access tool (RAT) written in Delphi that has been seen in the wild since the spring of 2010 and used by threat actors during Night Dragon.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1016
System Network Configuration Discovery

zwShell can obtain the victim IP address.

T1021.001
Remote Desktop Protocol

zwShell has used RDP for lateral movement.

T1021.002
SMB/Windows Admin Shares

zwShell has been copied over network shares to move laterally.

T1033
System Owner/User Discovery

zwShell can obtain the name of the logged-in user on the victim.

T1053.005
Scheduled Task

zwShell has used SchTasks for execution.

T1059.003
Windows Command Shell

zwShell can launch command-line shells.

T1070.004
File Deletion

zwShell has deleted itself after creating a service as well as deleted a temporary file when the system reboots.

T1082
System Information Discovery

zwShell can obtain the victim PC name and OS version.

T1083
File and Directory Discovery

zwShell can browse the file system.

T1112
Modify Registry

zwShell can modify the Registry.

T1543.003
Windows Service

zwShell has established persistence by adding itself as a new service.

Groups that use it0

None recorded.

Campaigns1

References1

  1. McAfee Night Dragon Open source
    McAfee® Foundstone® Professional Services and McAfee Labs™. (2011, February 10). Global Energy Cyberattacks: “Night Dragon”. Retrieved February 19, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.