ATT&CKSoftwareExaramel for Linux

Exaramel for Linux

S0401

Malware.View on attack.mitre.org

About this malware

Exaramel for Linux is a backdoor written in the Go Programming Language and compiled as a 64-bit ELF binary. The Windows version is tracked separately under Exaramel for Windows.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1008
Fallback Channels

Exaramel for Linux can attempt to find a new C2 server if it receives an error.

T1027.013
Encrypted/Encoded File

Exaramel for Linux uses RC4 for encrypting the configuration.

T1033
System Owner/User Discovery

Exaramel for Linux can run whoami to identify the system owner.

T1053.003
Cron

Exaramel for Linux uses crontab for persistence if it does not have root privileges.

T1059.004
Unix Shell

Exaramel for Linux has a command to execute a shell command on the system.

T1070.004
File Deletion

Exaramel for Linux can uninstall its persistence mechanism and delete its configuration file.

T1071.001
Web Protocols

Exaramel for Linux uses HTTPS for C2 communications.

T1105
Ingress Tool Transfer

Exaramel for Linux has a command to download a file from and to a remote C2 server.

T1140
Deobfuscate/Decode Files or Information

Exaramel for Linux can decrypt its configuration file.

T1543
Create or Modify System Process

Exaramel for Linux has a hardcoded location that it uses to achieve persistence if the startup system is Upstart or System V and it is running as root.

T1543.002
Systemd Service

Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root.

T1548.001
Setuid and Setgid

Exaramel for Linux can execute commands with high privileges via a specific binary with setuid functionality.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET TeleBots Oct 2018 Open source
    Cherepanov, A., Lipovsky, R. (2018, October 11). New TeleBots backdoor: First evidence linking Industroyer to NotPetya. Retrieved November 27, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.