PipeMon

S0501

Malware.View on attack.mitre.org

About this malware

PipeMon is a multi-stage modular backdoor used by Winnti Group.

Techniques used23

Procedure examples23

TechniqueProcedure example
T1008
Fallback Channels

PipeMon can switch to an alternate C2 domain when a particular date has been reached.

T1016
System Network Configuration Discovery

PipeMon can collect and send the local IP address, RDP information, and the network adapter physical address as a part of its C2 beacon.

T1027.011
Fileless Storage

PipeMon has stored its encrypted payload in the Registry under `HKLM\SOFTWARE\Microsoft\Print\Components\`.

T1027.013
Encrypted/Encoded File

PipeMon modules are stored encrypted on disk.

T1036.005
Match Legitimate Resource Name or Location

PipeMon modules are stored on disk with seemingly benign names including use of a file extension associated with a popular word processor.

T1055.001
Dynamic-link Library Injection

PipeMon can inject its modules into various processes using reflective DLL loading.

T1057
Process Discovery

PipeMon can iterate over the running processes to find a suitable injection target.

T1082
System Information Discovery

PipeMon can collect and send OS version and computer name as a part of its C2 beacon.

T1095
Non-Application Layer Protocol

The PipeMon communication module can use a custom protocol based on TLS over TCP.

T1105
Ingress Tool Transfer

PipeMon can install additional modules via C2 commands.

T1106
Native API

PipeMon's first stage has been executed by a call to CreateProcess with the decryption password in an argument. PipeMon has used a call to LoadLibrary to load its installer.

T1112
Modify Registry

PipeMon has modified the Registry to store its encrypted payload.

T1124
System Time Discovery

PipeMon can send time zone information from a compromised host to C2.

T1129
Shared Modules

PipeMon has used call to LoadLibrary to load its installer. PipeMon loads its modules using reflective loading or custom shellcode.

T1134.002
Create Process with Token

PipeMon can attempt to gain administrative privileges using token impersonation.

View all 23 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET PipeMon May 2020 Open source
    Tartare, M. et al. (2020, May 21). No “Game over” for the Winnti Group. Retrieved August 24, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.