HOPLIGHT

S0376

Malware.View on attack.mitre.org

About this malware

HOPLIGHT is a backdoor Trojan that has reportedly been used by the North Korean government.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1003.002
Security Account Manager

HOPLIGHT has the capability to harvest credentials and passwords from the SAM database.

T1008
Fallback Channels

HOPLIGHT has multiple C2 channels in place in case one fails.

T1012
Query Registry

A variant of HOPLIGHT hooks lsass.exe, and lsass.exe then checks the Registry for the data value 'rdpproto' under the key SYSTEM\CurrentControlSet\Control\Lsa Name.

T1041
Exfiltration Over C2 Channel

HOPLIGHT has used its C2 channel to exfiltrate data.

T1047
Windows Management Instrumentation

HOPLIGHT has used WMI to recompile the Managed Object Format (MOF) files in the WMI repository.

T1055
Process Injection

HOPLIGHT has injected into running processes.

T1059.003
Windows Command Shell

HOPLIGHT can launch cmd.exe to execute commands on the system.

T1082
System Information Discovery

HOPLIGHT has been observed collecting victim machine information like OS version.

T1083
File and Directory Discovery

HOPLIGHT has been observed enumerating system drives and partitions.

T1090
Proxy

HOPLIGHT has multiple proxy options that mask traffic between the malware and the remote operators.

T1105
Ingress Tool Transfer

HOPLIGHT has the ability to connect to a remote host in order to upload and download files.

T1112
Modify Registry

HOPLIGHT has modified Managed Object Format (MOF) files within the Registry to run specific commands and create persistence on the system.

T1124
System Time Discovery

HOPLIGHT has been observed collecting system time from victim machines.

T1132.001
Standard Encoding

HOPLIGHT has utilized Zlib compression to obfuscate the communications payload.

T1546.003
Windows Management Instrumentation Event Subscription

HOPLIGHT can use WMI event subscriptions to create persistence.

View all 21 procedure examples

Groups that use it2

Campaigns0

None recorded.

References1

  1. US-CERT HOPLIGHT Apr 2019 Open source
    US-CERT. (2019, April 10). MAR-10135536-8 – North Korean Trojan: HOPLIGHT. Retrieved April 19, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.