KeyBoy

S0387

Malware.View on attack.mitre.org

About this malware

KeyBoy is malware that has been used in targeted campaigns against members of the Tibetan Parliament in 2016.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic.

T1016
System Network Configuration Discovery

KeyBoy can determine the public or WAN IP address for the system.

T1027.013
Encrypted/Encoded File

In one version of KeyBoy, string obfuscation routines were used to hide many of the critical values referenced in the malware.

T1056.001
Keylogging

KeyBoy installs a keylogger for intercepting credentials and keystrokes.

T1059.001
PowerShell

KeyBoy uses PowerShell commands to download and execute payloads.

T1059.003
Windows Command Shell

KeyBoy can launch interactive shells for communicating with the victim machine.

T1059.005
Visual Basic

KeyBoy uses VBS scripts for installing files and performing execution.

T1059.006
Python

KeyBoy uses Python scripts for installing files and performing execution.

T1070.006
Timestomp

KeyBoy time-stomped its DLL in order to evade detection.

T1082
System Information Discovery

KeyBoy can gather extended system information, such as information about the operating system and memory.

T1083
File and Directory Discovery

KeyBoy has a command to launch a file browser or explorer on the system.

T1105
Ingress Tool Transfer

KeyBoy has a download and upload functionality.

T1113
Screen Capture

KeyBoy has a command to perform screen grabbing.

T1543.003
Windows Service

KeyBoy installs a service pointing to a malicious DLL dropped to disk.

T1547.004
Winlogon Helper DLL

KeyBoy issues the command reg add “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon” to achieve persistence.

View all 18 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. CitizenLab KeyBoy Nov 2016 Open source
    Hulcoop, A., et al. (2016, November 17). It’s Parliamentary KeyBoy and the targeting of the Tibetan Community. Retrieved June 13, 2019.
  2. PWC KeyBoys Feb 2017 Open source
    Parys, B. (2017, February 11). The KeyBoys are back in town. Retrieved June 13, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.