Malware.View on attack.mitre.org
HOPLIGHT is a backdoor Trojan that has reportedly been used by the North Korean government.
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
HOPLIGHT has the capability to harvest credentials and passwords from the SAM database. |
| T1008 Fallback Channels |
HOPLIGHT has multiple C2 channels in place in case one fails. |
| T1012 Query Registry |
A variant of HOPLIGHT hooks lsass.exe, and lsass.exe then checks the Registry for the data value 'rdpproto' under the key |
| T1041 Exfiltration Over C2 Channel |
HOPLIGHT has used its C2 channel to exfiltrate data. |
| T1047 Windows Management Instrumentation |
HOPLIGHT has used WMI to recompile the Managed Object Format (MOF) files in the WMI repository. |
| T1055 Process Injection |
HOPLIGHT has injected into running processes. |
| T1059.003 Windows Command Shell |
HOPLIGHT can launch cmd.exe to execute commands on the system. |
| T1082 System Information Discovery |
HOPLIGHT has been observed collecting victim machine information like OS version. |
| T1083 File and Directory Discovery |
HOPLIGHT has been observed enumerating system drives and partitions. |
| T1090 Proxy |
HOPLIGHT has multiple proxy options that mask traffic between the malware and the remote operators. |
| T1105 Ingress Tool Transfer |
HOPLIGHT has the ability to connect to a remote host in order to upload and download files. |
| T1112 Modify Registry |
HOPLIGHT has modified Managed Object Format (MOF) files within the Registry to run specific commands and create persistence on the system. |
| T1124 System Time Discovery |
HOPLIGHT has been observed collecting system time from victim machines. |
| T1132.001 Standard Encoding |
HOPLIGHT has utilized Zlib compression to obfuscate the communications payload. |
| T1546.003 Windows Management Instrumentation Event Subscription |
HOPLIGHT can use WMI event subscriptions to create persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.