Malware.View on attack.mitre.org
HotCroissant is a remote access trojan (RAT) attributed by U.S. government entities to malicious North Korean government cyber activity, tracked collectively as HIDDEN COBRA. HotCroissant shares numerous code similarities with Rifdoor.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
HotCroissant has the ability to retrieve a list of services on the infected host. |
| T1010 Application Window Discovery |
HotCroissant has the ability to list the names of all open windows on the infected host. |
| T1016 System Network Configuration Discovery |
HotCroissant has the ability to identify the IP address of the compromised machine. |
| T1027.002 Software Packing |
HotCroissant has used the open source UPX executable packer. |
| T1027.013 Encrypted/Encoded File |
HotCroissant has encrypted strings with single-byte XOR and base64 encoded RC4. |
| T1033 System Owner/User Discovery |
HotCroissant has the ability to collect the username on the infected host. |
| T1041 Exfiltration Over C2 Channel |
HotCroissant has the ability to download files from the infected host to the command and control (C2) server. |
| T1053.005 Scheduled Task |
HotCroissant has attempted to install a scheduled task named “Java Maintenance64” on startup to establish persistence. |
| T1057 Process Discovery |
HotCroissant has the ability to list running processes on the infected host. |
| T1059.003 Windows Command Shell |
HotCroissant can remotely open applications on the infected host with the |
| T1070.004 File Deletion |
HotCroissant has the ability to clean up installed files, delete files, and delete itself from the victim’s machine. |
| T1082 System Information Discovery |
HotCroissant has the ability to determine if the current user is an administrator, Windows product name, processor name, screen resolution, and physical RAM of the infected host. |
| T1083 File and Directory Discovery |
HotCroissant has the ability to retrieve a list of files in a given directory as well as drives and drive types. |
| T1105 Ingress Tool Transfer |
HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine. |
| T1106 Native API |
HotCroissant can perform dynamic DLL importing and API lookups using |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.