Avenger

S0473

Malware.View on attack.mitre.org

About this malware

Avenger is a downloader that has been used by BRONZE BUTLER since at least 2019.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1016
System Network Configuration Discovery

Avenger can identify the domain of the compromised host.

T1027.003
Steganography

Avenger can extract backdoor malware from downloaded images.

T1027.013
Encrypted/Encoded File

Avenger has the ability to XOR encrypt files to be sent to C2.

T1055
Process Injection

Avenger has the ability to inject shellcode into svchost.exe.

T1057
Process Discovery

Avenger has the ability to use Tasklist to identify running processes.

T1071.001
Web Protocols

Avenger has the ability to use HTTP in communication with C2.

T1082
System Information Discovery

Avenger has the ability to identify the OS architecture on a compromised host.

T1083
File and Directory Discovery

Avenger has the ability to browse files in directories such as Program Files and the Desktop.

T1105
Ingress Tool Transfer

Avenger has the ability to download files from C2 to a compromised host.

T1140
Deobfuscate/Decode Files or Information

Avenger has the ability to decrypt files downloaded from C2.

T1518.001
Security Software Discovery

Avenger has the ability to identify installed anti-virus products on a compromised host.

T1680
Local Storage Discovery

Avenger has the ability to identify the host volume ID.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro Tick November 2019 Open source
    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.