ATT&CKSoftwareBOOSTWRITE

BOOSTWRITE

S0415

Malware.View on attack.mitre.org

About this malware

BOOSTWRITE is a loader crafted to be launched via abuse of the DLL search order of applications used by FIN7.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

BOOSTWRITE has encoded its payloads using a ChaCha stream cipher with a 256-bit key and 64-bit Initialization vector (IV) to evade detection.

T1129
Shared Modules

BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules.

T1140
Deobfuscate/Decode Files or Information

BOOSTWRITE has used a a 32-byte long multi-XOR key to decode data inside its payload.

T1553.002
Code Signing

BOOSTWRITE has been signed by a valid CA.

T1574.001
DLL

BOOSTWRITE has exploited the loading of the legitimate Dwrite.dll file by actually loading the gdi library, which then loads the gdiplus library and ultimately loads the local Dwrite dll.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye FIN7 Oct 2019 Open source
    Carr, N, et all. (2019, October 10). Mahalo FIN7: Responding to the Criminal Operators’ New Tools and Techniques. Retrieved October 11, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.