Malware.View on attack.mitre.org
njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
njRAT can collect data from a local system. |
| T1010 Application Window Discovery |
njRAT gathers information about opened windows during the initial infection. |
| T1012 Query Registry |
njRAT can read specific registry values. |
| T1018 Remote System Discovery |
njRAT can identify remote hosts on connected networks. |
| T1021.001 Remote Desktop Protocol |
njRAT has a module for performing remote desktop access. |
| T1027.004 Compile After Delivery |
njRAT has used AutoIt to compile the payload and main script into a single executable after delivery. |
| T1027.013 Encrypted/Encoded File |
njRAT has included a base64 encoded executable. |
| T1033 System Owner/User Discovery |
njRAT enumerates the current user during the initial infection. |
| T1041 Exfiltration Over C2 Channel |
njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information. |
| T1056.001 Keylogging |
njRAT is capable of logging keystrokes. |
| T1057 Process Discovery |
njRAT can search a list of running processes for Tr.exe. |
| T1059.001 PowerShell |
njRAT has executed PowerShell commands via auto-run registry key persistence. |
| T1059.003 Windows Command Shell |
njRAT can launch a command shell interface for executing commands. |
| T1070.004 File Deletion |
njRAT is capable of deleting files. |
| T1070.009 Clear Persistence |
njRAT is capable of manipulating and deleting registry keys, including those used for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.