Pandora

S0664

Malware.View on attack.mitre.org

About this malware

Pandora is a multistage kernel rootkit with backdoor functionality that has been in use by Threat Group-3390 since at least 2020.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1027.015
Compression

Pandora has the ability to compress stings with QuickLZ.

T1055
Process Injection

Pandora can start and inject code into a new `svchost` process.

T1057
Process Discovery

Pandora can monitor processes on a compromised host.

T1068
Exploitation for Privilege Escalation

Pandora can use CVE-2017-15303 to bypass Windows Driver Signature Enforcement (DSE) protection and load its driver.

T1071.001
Web Protocols

Pandora can communicate over HTTP.

T1105
Ingress Tool Transfer

Pandora can load additional drivers and files onto a victim machine.

T1112
Modify Registry

Pandora can write an encrypted token to the Registry to enable processing of remote commands.

T1205
Traffic Signaling

Pandora can identify if incoming HTTP traffic contains a token and if so it will intercept the traffic and process the received command.

T1543.003
Windows Service

Pandora has the ability to gain system privileges through Windows services.

T1553.006
Code Signing Policy Modification

Pandora can use CVE-2017-15303 to disable Windows Driver Signature Enforcement (DSE) protection and load its driver.

T1569.002
Service Execution

Pandora has the ability to install itself as a Windows service.

T1573.001
Symmetric Cryptography

Pandora has the ability to encrypt communications with D3DES.

T1574.001
DLL

Pandora can use DLL side-loading to execute malicious payloads.

Groups that use it2

Campaigns0

None recorded.

References1

  1. Trend Micro Iron Tiger April 2021 Open source
    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.