ATT&CKSoftwareNativeZone

NativeZone

S0637

Malware.View on attack.mitre.org

About this malware

NativeZone is the name given collectively to disposable custom Cobalt Strike loaders used by APT29 since at least 2021.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1036
Masquerading

NativeZone has, upon execution, displayed a message box that appears to be related to a Ukrainian electronic document management system.

T1140
Deobfuscate/Decode Files or Information

NativeZone can decrypt and decode embedded Cobalt Strike beacon stage shellcode.

T1204.002
Malicious File

NativeZone can display an RTF document to the user to enable execution of Cobalt Strike stage shellcode.

T1218.011
Rundll32

NativeZone has used rundll32 to execute a malicious DLL.

T1480
Execution Guardrails

NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components.

T1497.001
System Checks

NativeZone has checked if Vmware or VirtualBox VM is running on a compromised host.

Groups that use it1

Campaigns0

None recorded.

References2

  1. MSTIC Nobelium Toolset May 2021 Open source
    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.
  2. SentinelOne NobleBaron June 2021 Open source
    Guerrero-Saade, J. (2021, June 1). NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks. Retrieved August 4, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.