ATT&CKSoftwarebuild_downer

build_downer

S0471

Malware.View on attack.mitre.org

About this malware

build_downer is a downloader that has been used by BRONZE BUTLER since at least 2019.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.003
Steganography

build_downer can extract malware from a downloaded JPEG.

T1036.004
Masquerade Task or Service

build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate.

T1105
Ingress Tool Transfer

build_downer has the ability to download files from C2 to the infected host.

T1106
Native API

build_downer has the ability to use the WinExec API to execute malware on a compromised host.

T1124
System Time Discovery

build_downer has the ability to determine the local time to ensure malware installation only happens during the hours that the infected system is active.

T1518.001
Security Software Discovery

build_downer has the ability to detect if the infected host is running an anti-virus process.

T1547.001
Registry Run Keys / Startup Folder

build_downer has the ability to add itself to the Registry Run key for persistence.

T1680
Local Storage Discovery

build_downer has the ability to send system volume information to C2.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro Tick November 2019 Open source
    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.