Malware.View on attack.mitre.org
ShimRat has been used by the suspected China-based adversary Mofang in campaigns targeting multiple countries and sectors including government, military, critical infrastructure, automobile, and weapons development. The name "ShimRat" comes from the malware's extensive use of Windows Application Shimming to maintain persistence.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
ShimRat has the capability to upload collected files to a C2. |
| T1008 Fallback Channels |
ShimRat has used a secondary C2 location if the first was unavailable. |
| T1027.002 Software Packing |
ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack. |
| T1027.015 Compression |
ShimRat has been delivered as a package that includes compressed DLL and shellcode payloads within a .dat file. |
| T1029 Scheduled Transfer |
ShimRat can sleep when instructed to do so by the C2. |
| T1036.004 Masquerade Task or Service |
ShimRat can impersonate Windows services and antivirus products to avoid detection on compromised systems. |
| T1059.003 Windows Command Shell |
ShimRat can be issued a command shell function from the C2. |
| T1070.004 File Deletion |
ShimRat can uninstall itself from compromised hosts, as well create and modify directories, delete, move, copy, and rename files. |
| T1071.001 Web Protocols |
ShimRat communicated over HTTP and HTTPS with C2 servers. |
| T1083 File and Directory Discovery |
ShimRat can list directories. |
| T1090.002 External Proxy |
ShimRat can use pre-configured HTTP proxies. |
| T1105 Ingress Tool Transfer |
ShimRat can download additional files. |
| T1106 Native API |
ShimRat has used Windows API functions to install the service and shim. |
| T1112 Modify Registry |
ShimRat has registered two registry keys for shim databases. |
| T1135 Network Share Discovery |
ShimRat can enumerate connected drives for infected host machines. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.