ATT&CKSoftwareTAINTEDSCRIBE

TAINTEDSCRIBE

S0586

Malware.View on attack.mitre.org

About this malware

TAINTEDSCRIBE is a fully-featured beaconing implant integrated with command modules used by Lazarus Group. It was first reported in May 2020.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

TAINTEDSCRIBE has used FakeTLS for session authentication.

T1008
Fallback Channels

TAINTEDSCRIBE can randomly pick one of five hard-coded IP addresses for C2 communication; if one of the IP fails, it will wait 60 seconds and then try another IP address.

T1018
Remote System Discovery

The TAINTEDSCRIBE command and execution module can perform target system enumeration.

T1027.001
Binary Padding

TAINTEDSCRIBE can execute FileRecvWriteRand to append random bytes to the end of a file received from C2.

T1036.005
Match Legitimate Resource Name or Location

The TAINTEDSCRIBE main executable has disguised itself as Microsoft’s Narrator.

T1057
Process Discovery

TAINTEDSCRIBE can execute ProcessList for process discovery.

T1059.003
Windows Command Shell

TAINTEDSCRIBE can enable Windows CLI access and execute files.

T1070.004
File Deletion

TAINTEDSCRIBE can delete files from a compromised host.

T1070.006
Timestomp

TAINTEDSCRIBE can change the timestamp of specified filenames.

T1083
File and Directory Discovery

TAINTEDSCRIBE can use DirectoryList to enumerate files in a specified directory.

T1105
Ingress Tool Transfer

TAINTEDSCRIBE can download additional modules from its C2 server.

T1124
System Time Discovery

TAINTEDSCRIBE can execute GetLocalTime for time discovery.

T1547.001
Registry Run Keys / Startup Folder

TAINTEDSCRIBE can copy itself into the current user’s Startup folder as “Narrator.exe” for persistence.

T1560
Archive Collected Data

TAINTEDSCRIBE has used FileReadZipSend to compress a file and send to C2.

T1573.001
Symmetric Cryptography

TAINTEDSCRIBE uses a Linear Feedback Shift Register (LFSR) algorithm for network encryption.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. CISA MAR-10288834-2.v1 TAINTEDSCRIBE MAY 2020 Open source
    USG. (2020, May 12). MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE. Retrieved March 5, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.