SideTwist

S0610

Malware.View on attack.mitre.org

About this malware

SideTwist is a C-based backdoor that has been used by OilRig since at least 2021.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1001
Data Obfuscation

SideTwist can embed C2 responses in the source code of a fake Flickr webpage.

T1005
Data from Local System

SideTwist has the ability to upload files from a compromised host.

T1008
Fallback Channels

SideTwist has primarily used port 443 for C2 but can use port 80 as a fallback.

T1016
System Network Configuration Discovery

SideTwist has the ability to collect the domain name on a compromised host.

T1033
System Owner/User Discovery

SideTwist can collect the username on a targeted system.

T1041
Exfiltration Over C2 Channel

SideTwist has exfiltrated data over its C2 channel.

T1059.003
Windows Command Shell

SideTwist can execute shell commands on a compromised host.

T1071.001
Web Protocols

SideTwist has used HTTP GET and POST requests over port 443 for C2.

T1082
System Information Discovery

SideTwist can collect the computer name of a targeted system.

T1083
File and Directory Discovery

SideTwist has the ability to search for specific files.

T1105
Ingress Tool Transfer

SideTwist has the ability to download additional files.

T1106
Native API

SideTwist can use GetUserNameW, GetComputerNameW, and GetComputerNameExW to gather information.

T1132.001
Standard Encoding

SideTwist has used Base64 for encoded C2 traffic.

T1140
Deobfuscate/Decode Files or Information

SideTwist can decode and decrypt messages received from C2.

T1573.001
Symmetric Cryptography

SideTwist can encrypt C2 communications with a randomly generated key.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Check Point APT34 April 2021 Open source
    Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.