Malware.View on attack.mitre.org
BabyShark is a Microsoft Visual Basic (VB) script-based malware family that is believed to be associated with several North Korean campaigns.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
BabyShark has executed the |
| T1016 System Network Configuration Discovery |
BabyShark has executed the |
| T1033 System Owner/User Discovery |
BabyShark has executed the |
| T1053.005 Scheduled Task |
BabyShark has used scheduled tasks to maintain persistence. |
| T1056.001 Keylogging |
BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger. |
| T1057 Process Discovery |
BabyShark has executed the |
| T1059.003 Windows Command Shell |
BabyShark has used cmd.exe to execute commands. |
| T1059.005 Visual Basic |
BabyShark can execute additional VisualBasic content. |
| T1070.004 File Deletion |
BabyShark has cleaned up all files associated with the secondary payload execution. |
| T1082 System Information Discovery |
BabyShark has executed the |
| T1083 File and Directory Discovery |
BabyShark has used |
| T1105 Ingress Tool Transfer |
BabyShark has downloaded additional files from the C2. |
| T1132.001 Standard Encoding |
BabyShark has encoded data using certutil before exfiltration. |
| T1140 Deobfuscate/Decode Files or Information |
BabyShark has the ability to decode downloaded files prior to execution. |
| T1218.005 Mshta |
BabyShark has used mshta.exe to download and execute applications from a remote server. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.