Malware.View on attack.mitre.org
TAINTEDSCRIBE is a fully-featured beaconing implant integrated with command modules used by Lazarus Group. It was first reported in May 2020.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
TAINTEDSCRIBE has used FakeTLS for session authentication. |
| T1008 Fallback Channels |
TAINTEDSCRIBE can randomly pick one of five hard-coded IP addresses for C2 communication; if one of the IP fails, it will wait 60 seconds and then try another IP address. |
| T1018 Remote System Discovery |
The TAINTEDSCRIBE command and execution module can perform target system enumeration. |
| T1027.001 Binary Padding |
TAINTEDSCRIBE can execute |
| T1036.005 Match Legitimate Resource Name or Location |
The TAINTEDSCRIBE main executable has disguised itself as Microsoft’s Narrator. |
| T1057 Process Discovery |
TAINTEDSCRIBE can execute |
| T1059.003 Windows Command Shell |
TAINTEDSCRIBE can enable Windows CLI access and execute files. |
| T1070.004 File Deletion |
TAINTEDSCRIBE can delete files from a compromised host. |
| T1070.006 Timestomp |
TAINTEDSCRIBE can change the timestamp of specified filenames. |
| T1083 File and Directory Discovery |
TAINTEDSCRIBE can use |
| T1105 Ingress Tool Transfer |
TAINTEDSCRIBE can download additional modules from its C2 server. |
| T1124 System Time Discovery |
TAINTEDSCRIBE can execute |
| T1547.001 Registry Run Keys / Startup Folder |
TAINTEDSCRIBE can copy itself into the current user’s Startup folder as “Narrator.exe” for persistence. |
| T1560 Archive Collected Data |
TAINTEDSCRIBE has used |
| T1573.001 Symmetric Cryptography |
TAINTEDSCRIBE uses a Linear Feedback Shift Register (LFSR) algorithm for network encryption. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.