EnvyScout

S0634

Malware.View on attack.mitre.org

About this malware

EnvyScout is a dropper that has been used by APT29 since at least 2021.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1005
Data from Local System

EnvyScout can collect sensitive NTLM material from a compromised host.

T1027.006
HTML Smuggling

EnvyScout contains JavaScript code that can extract an encoded blob from its HTML body and write it to disk.

T1027.013
Encrypted/Encoded File

EnvyScout can Base64 encode payloads.

T1036
Masquerading

EnvyScout has used folder icons for malicious files to lure victims into opening them.

T1059.003
Windows Command Shell

EnvyScout can use cmd.exe to execute malicious files on compromised hosts.

T1059.007
JavaScript

EnvyScout can write files to disk with JavaScript using a modified version of the open-source tool FileSaver.

T1082
System Information Discovery

EnvyScout can determine whether the ISO payload was received by a Windows or iOS device.

T1140
Deobfuscate/Decode Files or Information

EnvyScout can deobfuscate and write malicious ISO files to disk.

T1187
Forced Authentication

EnvyScout can use protocol handlers to coax the operating system to send NTLMv2 authentication responses to attacker-controlled infrastructure.

T1204.002
Malicious File

EnvyScout has been executed through malicious files attached to e-mails.

T1218.011
Rundll32

EnvyScout has the ability to proxy execution of malicious files with Rundll32.

T1480
Execution Guardrails

EnvyScout can call window.location.pathname to ensure that embedded files are being executed from the C: drive, and will terminate if they are not.

T1564.001
Hidden Files and Directories

EnvyScout can use hidden directories and files to hide malicious executables.

T1566.001
Spearphishing Attachment

EnvyScout has been distributed via spearphishing as an email attachment.

Groups that use it1

Campaigns0

None recorded.

References1

  1. MSTIC Nobelium Toolset May 2021 Open source
    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.