MarkiRAT

S0652

Malware.View on attack.mitre.org

About this malware

MarkiRAT is a remote access Trojan (RAT) compiled with Visual Studio that has been used by Ferocious Kitten since at least 2015.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1005
Data from Local System

MarkiRAT can upload data from the victim's machine to the C2 server.

T1033
System Owner/User Discovery

MarkiRAT can retrieve the victim’s username.

T1036.005
Match Legitimate Resource Name or Location

MarkiRAT can masquerade as update.exe and svehost.exe; it has also mimicked legitimate Telegram and Chrome files.

T1041
Exfiltration Over C2 Channel

MarkiRAT can exfiltrate locally stored data via its C2.

T1056.001
Keylogging

MarkiRAT can capture all keystrokes on a compromised host.

T1057
Process Discovery

MarkiRAT can search for different processes on a system.

T1059.003
Windows Command Shell

MarkiRAT can utilize cmd.exe to execute commands in a victim's environment.

T1071.001
Web Protocols

MarkiRAT can initiate communication over HTTP/HTTPS for its C2 server.

T1074.001
Local Data Staging

MarkiRAT can store collected data locally in a created .nfo file.

T1082
System Information Discovery

MarkiRAT can obtain the computer name from a compromised host.

T1083
File and Directory Discovery

MarkiRAT can look for files carrying specific extensions such as: .rtf, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pps, .ppsx, .txt, .gpg, .pkr, .kdbx, .key, and .jpb.

T1105
Ingress Tool Transfer

MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin.

T1106
Native API

MarkiRAT can run the ShellExecuteW API via the Windows Command Shell.

T1113
Screen Capture

MarkiRAT can capture screenshots that are initially saved as ‘scr.jpg’.

T1115
Clipboard Data

MarkiRAT can capture clipboard content.

View all 22 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky Ferocious Kitten Jun 2021 Open source
    GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.