RCSession

S0662

Malware.View on attack.mitre.org

About this malware

RCSession is a backdoor written in C++ that has been in use since at least 2018 by Mustang Panda and by Threat Group-3390 (Type II Backdoor).

Techniques used22

Procedure examples22

TechniqueProcedure example
T1005
Data from Local System

RCSession can collect data from a compromised host.

T1027.011
Fileless Storage

RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`.

T1027.015
Compression

RCSession can compress and obfuscate its strings to evade detection on a compromised host.

T1033
System Owner/User Discovery

RCSession can gather system owner information, including user and administrator privileges.

T1036
Masquerading

RCSession has used a file named English.rtf to appear benign on victim hosts.

T1055.012
Process Hollowing

RCSession can launch itself from a hollowed svchost.exe process.

T1056.001
Keylogging

RCSession has the ability to capture keystrokes on a compromised host.

T1057
Process Discovery

RCSession can identify processes based on PID.

T1059.003
Windows Command Shell

RCSession can use `cmd.exe` for execution on compromised hosts.

T1070.004
File Deletion

RCSession can remove files from a targeted system.

T1071.001
Web Protocols

RCSession can use HTTP in C2 communications.

T1082
System Information Discovery

RCSession can gather system information from a compromised host.

T1095
Non-Application Layer Protocol

RCSession has the ability to use TCP and UDP in C2 communications.

T1105
Ingress Tool Transfer

RCSession has the ability to drop additional files to an infected machine.

T1106
Native API

RCSession can use WinSock API for communication including WSASend and WSARecv.

View all 22 procedure examples

Groups that use it2

Campaigns0

None recorded.

References3

  1. Secureworks BRONZE PRESIDENT December 2019 Open source
    Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.
  2. Trend Micro DRBControl February 2020 Open source
    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.
  3. Trend Micro Iron Tiger April 2021 Open source
    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.