Malware.View on attack.mitre.org
SodaMaster is a fileless malware used by menuPass to download and execute payloads since at least 2020.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
SodaMaster has the ability to query the Registry to detect a key specific to VMware. |
| T1027 Obfuscated Files or Information |
SodaMaster can use "stackstrings" for obfuscation. |
| T1033 System Owner/User Discovery |
SodaMaster can identify the username on a compromised host. |
| T1057 Process Discovery |
SodaMaster can search a list of running processes. |
| T1082 System Information Discovery |
SodaMaster can enumerate the host name and OS version on a target system. |
| T1105 Ingress Tool Transfer |
SodaMaster has the ability to download additional payloads from C2 to the targeted system. |
| T1106 Native API |
SodaMaster can use |
| T1497.001 System Checks |
SodaMaster can check for the presence of the Registry key |
| T1497.003 Time Based Checks |
SodaMaster has the ability to put itself to "sleep" for a specified time. |
| T1573.001 Symmetric Cryptography |
SodaMaster can use RC4 to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
SodaMaster can use a hardcoded RSA key to encrypt some of its C2 traffic. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.