Waterbear

S0579

Malware.View on attack.mitre.org

About this malware

Waterbear is modular malware attributed to BlackTech that has been used primarily for lateral movement, decrypting, and triggering payloads and is capable of hiding network behaviors.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1012
Query Registry

Waterbear can query the Registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\MTxOCI" to see if the value `OracleOcilib` exists.

T1027.005
Indicator Removal from Tools

Waterbear can scramble functions not to be executed again with random values.

T1027.013
Encrypted/Encoded File

Waterbear has used RC4 encrypted shellcode and encrypted functions.

T1049
System Network Connections Discovery

Waterbear can use API hooks on `GetExtendedTcpTable` to retrieve a table containing a list of TCP endpoints available to the application.

T1055
Process Injection

Waterbear can inject decrypted shellcode into the LanmanServer service.

T1055.003
Thread Execution Hijacking

Waterbear can use thread injection to inject shellcode into the process of security software.

T1057
Process Discovery

Waterbear can identify the process for a specific security product.

T1105
Ingress Tool Transfer

Waterbear can receive and load executables from remote C2 servers.

T1106
Native API

Waterbear can leverage API functions for execution.

T1112
Modify Registry

Waterbear has deleted certain values from the Registry to load a malicious DLL.

T1140
Deobfuscate/Decode Files or Information

Waterbear has the ability to decrypt its RC4 encrypted payload for execution.

T1518.001
Security Software Discovery

Waterbear can find the presence of a specific security software.

T1574.001
DLL

Waterbear has used DLL side loading to import and load a malicious DLL loader.

T1685
Disable or Modify Tools

Waterbear can hook the ZwOpenProcess and GetExtendedTcpTable APIs called by the process of a security product to hide PIDs and TCP records from detection.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro Waterbear December 2019 Open source
    Su, V. et al. (2019, December 11). Waterbear Returns, Uses API Hooking to Evade Security. Retrieved February 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.