Kerrdown

S0585

Malware.View on attack.mitre.org

About this malware

Kerrdown is a custom downloader that has been used by APT32 since at least 2018 to install spyware from a server on the victim's network.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Kerrdown can encrypt, encode, and compress multiple layers of shellcode.

T1027.015
Compression

Kerrdown can encrypt, encode, and compress multiple layers of shellcode.

T1059.005
Visual Basic

Kerrdown can use a VBS base64 decoder function published by Motobit.

T1082
System Information Discovery

Kerrdown has the ability to determine if the compromised host is running a 32 or 64 bit OS architecture.

T1105
Ingress Tool Transfer

Kerrdown can download specific payloads to a compromised host based on OS architecture.

T1140
Deobfuscate/Decode Files or Information

Kerrdown can decode, decrypt, and decompress multiple layers of shellcode.

T1204.001
Malicious Link

Kerrdown has gained execution through victims opening malicious links.

T1204.002
Malicious File

Kerrdown has gained execution through victims opening malicious files.

T1566.001
Spearphishing Attachment

Kerrdown has been distributed through malicious e-mail attachments.

T1566.002
Spearphishing Link

Kerrdown has been distributed via e-mails containing a malicious link.

T1574.001
DLL

Kerrdown can use DLL side-loading to load malicious DLLs.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Amnesty Intl. Ocean Lotus February 2021 Open source
    Amnesty International. (2021, February 24). Vietnamese activists targeted by notorious hacking group. Retrieved March 1, 2021.
  2. Unit 42 KerrDown February 2019 Open source
    Ray, V. and Hayashi, K. (2019, February 1). Tracking OceanLotus’ new Downloader, KerrDown. Retrieved October 1, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.