Clambling

S0660

Malware.View on attack.mitre.org

About this malware

Clambling is a modular backdoor written in C++ that has been used by Threat Group-3390 since at least 2017.

Techniques used34

Procedure examples34

TechniqueProcedure example
T1005
Data from Local System

Clambling can collect information from a compromised host.

T1012
Query Registry

Clambling has the ability to enumerate Registry keys, including KEY_CURRENT_USER\Software\Bitcoin\Bitcoin-Qt\strDataDir to search for a bitcoin wallet.

T1016
System Network Configuration Discovery

Clambling can enumerate the IP address of a compromised machine.

T1027
Obfuscated Files or Information

The Clambling executable has been obfuscated when dropped on a compromised host.

T1033
System Owner/User Discovery

Clambling can identify the username on a compromised host.

T1055
Process Injection

Clambling can inject into the `svchost.exe` process for execution.

T1055.012
Process Hollowing

Clambling can execute binaries through process hollowing.

T1056.001
Keylogging

Clambling can capture keystrokes on a compromised host.

T1057
Process Discovery

Clambling can enumerate processes on a targeted system.

T1059.001
PowerShell

The Clambling dropper can use PowerShell to download the malware.

T1059.003
Windows Command Shell

Clambling can use cmd.exe for command execution.

T1071
Application Layer Protocol

Clambling has the ability to use Telnet for communication.

T1071.001
Web Protocols

Clambling has the ability to communicate over HTTP.

T1082
System Information Discovery

Clambling can discover the hostname, computer name, and Windows version of a targeted machine.

T1083
File and Directory Discovery

Clambling can browse directories on a compromised host.

View all 34 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro DRBControl February 2020 Open source
    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.