ATT&CKSoftwareSodaMaster

SodaMaster

S0627

Malware.View on attack.mitre.org

About this malware

SodaMaster is a fileless malware used by menuPass to download and execute payloads since at least 2020.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1012
Query Registry

SodaMaster has the ability to query the Registry to detect a key specific to VMware.

T1027
Obfuscated Files or Information

SodaMaster can use "stackstrings" for obfuscation.

T1033
System Owner/User Discovery

SodaMaster can identify the username on a compromised host.

T1057
Process Discovery

SodaMaster can search a list of running processes.

T1082
System Information Discovery

SodaMaster can enumerate the host name and OS version on a target system.

T1105
Ingress Tool Transfer

SodaMaster has the ability to download additional payloads from C2 to the targeted system.

T1106
Native API

SodaMaster can use RegOpenKeyW to access the Registry.

T1497.001
System Checks

SodaMaster can check for the presence of the Registry key HKEY_CLASSES_ROOT\\Applications\\VMwareHostOpen.exe before proceeding to its main functionality.

T1497.003
Time Based Checks

SodaMaster has the ability to put itself to "sleep" for a specified time.

T1573.001
Symmetric Cryptography

SodaMaster can use RC4 to encrypt C2 communications.

T1573.002
Asymmetric Cryptography

SodaMaster can use a hardcoded RSA key to encrypt some of its C2 traffic.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Securelist APT10 March 2021 Open source
    GREAT. (2021, March 30). APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign. Retrieved June 17, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.