Explosive

S0569

Malware.View on attack.mitre.org

About this malware

Explosive is a custom-made remote access tool used by the group Volatile Cedar. It was first identified in the wild in 2015.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1016
System Network Configuration Discovery

Explosive has collected the MAC address from the victim's machine.

T1025
Data from Removable Media

Explosive can scan all .exe files located in the USB drive.

T1033
System Owner/User Discovery

Explosive has collected the username from the infected host.

T1056.001
Keylogging

Explosive has leveraged its keylogging capabilities to gain access to administrator accounts on target servers.

T1071.001
Web Protocols

Explosive has used HTTP for communication.

T1082
System Information Discovery

Explosive has collected the computer name from the infected host.

T1105
Ingress Tool Transfer

Explosive has a function to download a file to the infected system.

T1106
Native API

Explosive has a function to call the OpenClipboard wrapper.

T1112
Modify Registry

Explosive has a function to write itself to Registry values.

T1115
Clipboard Data

Explosive has a function to use the OpenClipboard wrapper.

T1564.001
Hidden Files and Directories

Explosive has commonly set file and path attributes to hidden.

T1573.001
Symmetric Cryptography

Explosive has encrypted communications with the RC4 method.

Groups that use it1

Campaigns0

None recorded.

References2

  1. CheckPoint Volatile Cedar March 2015 Open source
    Threat Intelligence and Research. (2015, March 30). VOLATILE CEDAR. Retrieved February 8, 2021.
  2. ClearSky Lebanese Cedar Jan 2021 Open source
    ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.