SoreFang

S0516

Malware.View on attack.mitre.org

About this malware

SoreFang is first stage downloader used by APT29 for exfiltration and to load other malware.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1016
System Network Configuration Discovery

SoreFang can collect the TCP/IP, DNS, DHCP, and network adapter configuration on a compromised host via ipconfig.exe /all.

T1027
Obfuscated Files or Information

SoreFang has the ability to encode and RC6 encrypt data sent to C2.

T1053.005
Scheduled Task

SoreFang can gain persistence through use of scheduled tasks.

T1057
Process Discovery

SoreFang can enumerate processes on a victim machine through use of Tasklist.

T1069.002
Domain Groups

SoreFang can enumerate domain groups by executing net.exe group /domain.

T1071.001
Web Protocols

SoreFang can use HTTP in C2 communications.

T1082
System Information Discovery

SoreFang can collect the hostname, operating system configuration, and product ID on victim machines by executing Systeminfo.

T1083
File and Directory Discovery

SoreFang has the ability to list directories.

T1087.001
Local Account

SoreFang can collect usernames from the local system via net.exe user.

T1087.002
Domain Account

SoreFang can enumerate domain accounts via net.exe user /domain.

T1105
Ingress Tool Transfer

SoreFang can download additional payloads from C2.

T1140
Deobfuscate/Decode Files or Information

SoreFang can decode and decrypt exfiltrated data sent to C2.

T1190
Exploit Public-Facing Application

SoreFang can gain access by exploiting a Sangfor SSL VPN vulnerability that allows for the placement and delivery of malicious update binaries.

T1680
Local Storage Discovery

SoreFang can collect disk space information on victim machines by executing Systeminfo.

Groups that use it1

Campaigns0

None recorded.

References2

  1. CISA SoreFang July 2016 Open source
    CISA. (2020, July 16). MAR-10296782-1.v1 – SOREFANG. Retrieved September 29, 2020.
  2. NCSC APT29 July 2020 Open source
    National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.