TajMahal

S0467

Malware.View on attack.mitre.org

About this malware

TajMahal is a multifunctional spying framework that has been in use since at least 2014. TajMahal is comprised of two separate packages, named Tokyo and Yokohama, and can deploy up to 80 plugins.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1005
Data from Local System

TajMahal has the ability to steal documents from the local system including the print spooler queue.

T1016
System Network Configuration Discovery

TajMahal has the ability to identify the MAC address on an infected host.

T1020
Automated Exfiltration

TajMahal has the ability to manage an automated queue of egress files and commands sent to its C2.

T1025
Data from Removable Media

TajMahal has the ability to steal written CD images and files of interest from previously connected removable drives when they become available again.

T1027
Obfuscated Files or Information

TajMahal has used an encrypted Virtual File System to store plugins.

T1041
Exfiltration Over C2 Channel

TajMahal has the ability to send collected files over its C2.

T1055.001
Dynamic-link Library Injection

TajMahal has the ability to inject DLLs for malicious plugins into running processes.

T1056.001
Keylogging

TajMahal has the ability to capture keystrokes on an infected host.

T1057
Process Discovery

TajMahal has the ability to identify running processes and associated plugins on an infected host.

T1082
System Information Discovery

TajMahal has the ability to identify hardware information, the computer name, and OS information on an infected host.

T1083
File and Directory Discovery

TajMahal has the ability to index files from drives, user profiles, and removable drives.

T1112
Modify Registry

TajMahal can set the KeepPrintedJobs attribute for configured printers in SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Print\\Printers to enable document stealing.

T1113
Screen Capture

TajMahal has the ability to take screenshots on an infected host including capturing content from windows of instant messaging applications.

T1115
Clipboard Data

TajMahal has the ability to steal data from the clipboard of an infected host.

T1119
Automated Collection

TajMahal has the ability to index and compress files into a send queue for exfiltration.

View all 24 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Kaspersky TajMahal April 2019 Open source
    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.