Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1001 Data Obfuscation |
Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests. |
| T1001.003 Protocol or Service Impersonation |
Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests. |
| T1003.001 LSASS Memory |
Okrum was seen using MimikatzLite to perform credential dumping. |
| T1003.005 Cached Domain Credentials |
Okrum was seen using modified Quarks PwDump to perform credential dumping. |
| T1016 System Network Configuration Discovery |
Okrum can collect network information, including the host IP address, DNS, and proxy information. |
| T1027.003 Steganography |
Okrum's payload is encrypted and embedded within its loader, or within a legitimate PNG file. |
| T1033 System Owner/User Discovery |
Okrum can collect the victim username. |
| T1036.004 Masquerade Task or Service |
Okrum can establish persistence by adding a new service NtmsSvc with the display name Removable Storage to masquerade as a legitimate Removable Storage Manager. |
| T1041 Exfiltration Over C2 Channel |
Data exfiltration is done by Okrum using the already opened channel with the C2 server. |
| T1049 System Network Connections Discovery |
Okrum was seen using NetSess to discover NetBIOS sessions. |
| T1053.005 Scheduled Task |
Okrum's installer can attempt to achieve persistence by creating a scheduled task. |
| T1056.001 Keylogging |
Okrum was seen using a keylogger tool to capture keystrokes. |
| T1059.003 Windows Command Shell |
Okrum's backdoor has used cmd.exe to execute arbitrary commands as well as batch scripts to update itself to a newer version. |
| T1070.004 File Deletion |
Okrum's backdoor deletes files after they have been successfully uploaded to C2 servers. |
| T1071.001 Web Protocols |
Okrum uses HTTP for communication with its C2. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.