ABK

S0469

Malware.View on attack.mitre.org

About this malware

ABK is a downloader that has been used by BRONZE BUTLER since at least 2019.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1027.003
Steganography

ABK can extract a malicious Portable Executable (PE) from a photo.

T1055
Process Injection

ABK has the ability to inject shellcode into svchost.exe.

T1059.003
Windows Command Shell

ABK has the ability to use cmd to run a Portable Executable (PE) on the compromised host.

T1071.001
Web Protocols

ABK has the ability to use HTTP in communications with C2.

T1105
Ingress Tool Transfer

ABK has the ability to download files from C2.

T1140
Deobfuscate/Decode Files or Information

ABK has the ability to decrypt AES encrypted payloads.

T1518.001
Security Software Discovery

ABK has the ability to identify the installed anti-virus product on the compromised host.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro Tick November 2019 Open source
    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.