Malware.View on attack.mitre.org
zwShell is a remote access tool (RAT) written in Delphi that has been seen in the wild since the spring of 2010 and used by threat actors during Night Dragon.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
zwShell can obtain the victim IP address. |
| T1021.001 Remote Desktop Protocol |
zwShell has used RDP for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
zwShell has been copied over network shares to move laterally. |
| T1033 System Owner/User Discovery |
zwShell can obtain the name of the logged-in user on the victim. |
| T1053.005 Scheduled Task |
zwShell has used SchTasks for execution. |
| T1059.003 Windows Command Shell |
zwShell can launch command-line shells. |
| T1070.004 File Deletion |
zwShell has deleted itself after creating a service as well as deleted a temporary file when the system reboots. |
| T1082 System Information Discovery |
zwShell can obtain the victim PC name and OS version. |
| T1083 File and Directory Discovery |
zwShell can browse the file system. |
| T1112 Modify Registry |
zwShell can modify the Registry. |
| T1543.003 Windows Service |
zwShell has established persistence by adding itself as a new service. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.