Spark

S0543

Malware.View on attack.mitre.org

About this malware

Spark is a Windows backdoor and has been in use since as early as 2017.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1027.002
Software Packing

Spark has been packed with Enigma Protector to obfuscate its contents.

T1033
System Owner/User Discovery

Spark has run the whoami command and has a built-in command to identify the user logged in.

T1041
Exfiltration Over C2 Channel

Spark has exfiltrated data over the C2 channel.

T1059.003
Windows Command Shell

Spark can use cmd.exe to run commands.

T1071.001
Web Protocols

Spark has used HTTP POST requests to communicate with its C2 server to receive commands.

T1082
System Information Discovery

Spark can collect the hostname, keyboard layout, and language from the system.

T1132.001
Standard Encoding

Spark has encoded communications with the C2 server with base64.

T1140
Deobfuscate/Decode Files or Information

Spark has used a custom XOR algorithm to decrypt the payload.

T1497.002
User Activity Based Checks

Spark has used a splash screen to check whether an user actively clicks on the screen before running malicious code.

T1614.001
System Language Discovery

Spark has checked the results of the GetKeyboardLayoutList and the language name returned by GetLocaleInfoA to make sure they contain the word “Arabic” before executing.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit42 Molerat Mar 2020 Open source
    Falcone, R., et al. (2020, March 3). Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations. Retrieved December 14, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.