Cannon

S0351

Malware.View on attack.mitre.org

About this malware

Cannon is a Trojan with variants written in C# and Delphi. It was first observed in April 2018.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1033
System Owner/User Discovery

Cannon can gather the username from the system.

T1041
Exfiltration Over C2 Channel

Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels.

T1057
Process Discovery

Cannon can obtain a list of processes running on the system.

T1071.003
Mail Protocols

Cannon uses SMTP/S and POP3/S for C2 communications by sending and receiving emails.

T1082
System Information Discovery

Cannon can gather system information from the victim’s machine such as the OS version, and machine name.

T1083
File and Directory Discovery

Cannon can obtain victim drive information as well as a list of folders in C:\Program Files.

T1105
Ingress Tool Transfer

Cannon can download a payload for execution.

T1113
Screen Capture

Cannon can take a screenshot of the desktop.

T1124
System Time Discovery

Cannon can collect the current time zone information from the victim’s machine.

T1547.004
Winlogon Helper DLL

Cannon adds the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon to establish persistence.

T1680
Local Storage Discovery

Cannon can gather drive information from the victim's machine.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Unit42 Cannon Nov 2018 Open source
    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.
  2. Unit42 Sofacy Dec 2018 Open source
    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.