CARROTBAT

S0462

Malware.View on attack.mitre.org

About this malware

CARROTBAT is a customized dropper that has been in use since at least 2017. CARROTBAT has been used to install SYSCON and has infrastructure overlap with KONNI.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.010
Command Obfuscation

CARROTBAT has the ability to execute obfuscated commands on the infected host.

T1027.013
Encrypted/Encoded File

CARROTBAT has the ability to download a base64 encoded payload.

T1059.003
Windows Command Shell

CARROTBAT has the ability to execute command line arguments on a compromised host.

T1070.004
File Deletion

CARROTBAT has the ability to delete downloaded files from a compromised host.

T1082
System Information Discovery

CARROTBAT has the ability to determine the operating system of the compromised host and whether Windows is being run with x86 or x64 architecture.

T1105
Ingress Tool Transfer

CARROTBAT has the ability to download and execute a remote file via certutil.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Unit 42 CARROTBAT January 2020 Open source
    McCabe, A. (2020, January 23). The Fractured Statue Campaign: U.S. Government Agency Targeted in Spear-Phishing Attacks. Retrieved June 2, 2020.
  2. Unit 42 CARROTBAT November 2018 Open source
    Grunzweig, J. and Wilhoit, K. (2018, November 29). The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia. Retrieved June 2, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.