CSPY Downloader is a tool designed to evade analysis and download additional payloads used by Kimsuky.
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
CSPY Downloader has been packed with UPX. |
| T1036.004 Masquerade Task or Service |
CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications. |
| T1053.005 Scheduled Task |
CSPY Downloader can use the schtasks utility to bypass UAC. |
| T1070 Indicator Removal |
CSPY Downloader has the ability to remove values it writes to the Registry. |
| T1070.004 File Deletion |
CSPY Downloader has the ability to self delete. |
| T1071.001 Web Protocols |
CSPY Downloader can use GET requests to download additional payloads from C2. |
| T1105 Ingress Tool Transfer |
CSPY Downloader can download additional tools to a compromised host. |
| T1112 Modify Registry |
CSPY Downloader can write to the Registry under the |
| T1204.002 Malicious File |
CSPY Downloader has been delivered via malicious documents with embedded macros. |
| T1497.001 System Checks |
CSPY Downloader can search loaded modules, PEB structure, file paths, Registry keys, and memory to determine if it is being debugged or running in a virtual environment. |
| T1548.002 Bypass User Account Control |
CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges. |
| T1553.002 Code Signing |
CSPY Downloader has come signed with revoked certificates. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.