Ecipekac

S0624

Malware.View on attack.mitre.org

About this malware

Ecipekac is a multi-layer loader that has been used by menuPass since at least 2019 including use as a loader for P8RAT, SodaMaster, and FYAnti.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1027
Obfuscated Files or Information

Ecipekac can use XOR, AES, and DES to encrypt loader shellcode.

T1105
Ingress Tool Transfer

Ecipekac can download additional payloads to a compromised host.

T1140
Deobfuscate/Decode Files or Information

Ecipekac has the ability to decrypt fileless loader modules.

T1553.002
Code Signing

Ecipekac has used a valid, legitimate digital signature to evade detection.

T1574.001
DLL

Ecipekac can abuse the legitimate application policytool.exe to load a malicious DLL.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Securelist APT10 March 2021 Open source
    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.