ATT&CKSoftwareHiddenWasp

HiddenWasp

S0394

Malware.View on attack.mitre.org

About this malware

HiddenWasp is a Linux-based Trojan used to target systems for remote control. It comes in the form of a statically linked ELF binary with stdlibc++.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1014
Rootkit

HiddenWasp uses a rootkit to hook and implement functions on the system.

T1027.013
Encrypted/Encoded File

HiddenWasp encrypts its configuration and payload.

T1037.004
RC Scripts

HiddenWasp installs reboot persistence by adding itself to /etc/rc.local.

T1059.003
Windows Command Shell

HiddenWasp uses a script to automate tasks on the victim's machine and to assist in execution.

T1095
Non-Application Layer Protocol

HiddenWasp communicates with a simple network protocol over TCP.

T1105
Ingress Tool Transfer

HiddenWasp downloads a tar compressed archive from a download server to the system.

T1136.001
Local Account

HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine.

T1140
Deobfuscate/Decode Files or Information

HiddenWasp uses a cipher to implement a decoding function.

T1573.001
Symmetric Cryptography

HiddenWasp uses an RC4-like algorithm with an already computed PRGA generated key-stream for network communication.

T1574.006
Dynamic Linker Hijacking

HiddenWasp adds itself as a shared object to the LD_PRELOAD environment variable.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Intezer HiddenWasp Map 2019 Open source
    Sanmillan, I. (2019, May 29). HiddenWasp Malware Stings Targeted Linux Systems. Retrieved June 24, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.