ShimRat

S0444

Malware.View on attack.mitre.org

About this malware

ShimRat has been used by the suspected China-based adversary Mofang in campaigns targeting multiple countries and sectors including government, military, critical infrastructure, automobile, and weapons development. The name "ShimRat" comes from the malware's extensive use of Windows Application Shimming to maintain persistence.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1005
Data from Local System

ShimRat has the capability to upload collected files to a C2.

T1008
Fallback Channels

ShimRat has used a secondary C2 location if the first was unavailable.

T1027.002
Software Packing

ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack.

T1027.015
Compression

ShimRat has been delivered as a package that includes compressed DLL and shellcode payloads within a .dat file.

T1029
Scheduled Transfer

ShimRat can sleep when instructed to do so by the C2.

T1036.004
Masquerade Task or Service

ShimRat can impersonate Windows services and antivirus products to avoid detection on compromised systems.

T1059.003
Windows Command Shell

ShimRat can be issued a command shell function from the C2.

T1070.004
File Deletion

ShimRat can uninstall itself from compromised hosts, as well create and modify directories, delete, move, copy, and rename files.

T1071.001
Web Protocols

ShimRat communicated over HTTP and HTTPS with C2 servers.

T1083
File and Directory Discovery

ShimRat can list directories.

T1090.002
External Proxy

ShimRat can use pre-configured HTTP proxies.

T1105
Ingress Tool Transfer

ShimRat can download additional files.

T1106
Native API

ShimRat has used Windows API functions to install the service and shim.

T1112
Modify Registry

ShimRat has registered two registry keys for shim databases.

T1135
Network Share Discovery

ShimRat can enumerate connected drives for infected host machines.

View all 21 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. FOX-IT May 2016 Mofang Open source
    Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.