YAHOYAH

S0388

Malware.View on attack.mitre.org

About this malware

YAHOYAH is a Trojan used by Tropic Trooper as a second-stage backdoor.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

YAHOYAH encrypts its configuration file using a simple algorithm.

T1071.001
Web Protocols

YAHOYAH uses HTTP for C2.

T1082
System Information Discovery

YAHOYAH checks for the system’s Windows OS version and hostname.

T1105
Ingress Tool Transfer

YAHOYAH uses HTTP GET requests to download other files that are executed in memory.

T1140
Deobfuscate/Decode Files or Information

YAHOYAH decrypts downloaded files before execution.

T1518.001
Security Software Discovery

YAHOYAH checks for antimalware solution processes on the system.

Groups that use it1

Campaigns0

None recorded.

References1

  1. TrendMicro TropicTrooper 2015 Open source
    Alintanahin, K. (2015). Operation Tropic Trooper: Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers. Retrieved June 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.