Malware.View on attack.mitre.org
NativeZone is the name given collectively to disposable custom Cobalt Strike loaders used by APT29 since at least 2021.
| Technique | Procedure example |
|---|---|
| T1036 Masquerading |
NativeZone has, upon execution, displayed a message box that appears to be related to a Ukrainian electronic document management system. |
| T1140 Deobfuscate/Decode Files or Information |
NativeZone can decrypt and decode embedded Cobalt Strike beacon stage shellcode. |
| T1204.002 Malicious File |
NativeZone can display an RTF document to the user to enable execution of Cobalt Strike stage shellcode. |
| T1218.011 Rundll32 |
NativeZone has used rundll32 to execute a malicious DLL. |
| T1480 Execution Guardrails |
NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components. |
| T1497.001 System Checks |
NativeZone has checked if Vmware or VirtualBox VM is running on a compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.