Malware.View on attack.mitre.org
SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017. It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.
In October 2020, Kaspersky Labs assessed SLOTHFULMEDIA is part of an activity cluster it refers to as "IAmTheKing". ESET also noted code similarity between SLOTHFULMEDIA and droppers used by a group it refers to as "PowerPool".
| Technique | Procedure example |
|---|---|
| T1001 Data Obfuscation |
SLOTHFULMEDIA has hashed a string containing system information prior to exfiltration via POST requests. |
| T1005 Data from Local System |
SLOTHFULMEDIA has uploaded files and information from victim machines. |
| T1007 System Service Discovery |
SLOTHFULMEDIA has the capability to enumerate services. |
| T1033 System Owner/User Discovery |
SLOTHFULMEDIA has collected the username from a victim machine. |
| T1036.004 Masquerade Task or Service |
SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose. |
| T1036.005 Match Legitimate Resource Name or Location |
SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe. |
| T1041 Exfiltration Over C2 Channel |
SLOTHFULMEDIA has sent system information to a C2 server via HTTP and HTTPS POST requests. |
| T1049 System Network Connections Discovery |
SLOTHFULMEDIA can enumerate open ports on a victim machine. |
| T1055 Process Injection |
SLOTHFULMEDIA can inject into running processes on a compromised host. |
| T1056.001 Keylogging |
SLOTHFULMEDIA has a keylogging capability. |
| T1057 Process Discovery |
SLOTHFULMEDIA has enumerated processes by ID, name, or privileges. |
| T1059.003 Windows Command Shell |
SLOTHFULMEDIA can open a command line to execute commands. |
| T1070.004 File Deletion |
SLOTHFULMEDIA has deleted itself and the 'index.dat' file on a compromised machine to remove recent Internet history from the system. |
| T1071.001 Web Protocols |
SLOTHFULMEDIA has used HTTP and HTTPS for C2 communications. |
| T1082 System Information Discovery |
SLOTHFULMEDIA has collected system name, OS version, adapter information, and memory usage from a victim machine. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.