ATT&CKSoftwareThreatNeedle

ThreatNeedle

S0665

Malware.View on attack.mitre.org

About this malware

ThreatNeedle is a backdoor that has been used by Lazarus Group since at least 2019 to target cryptocurrency, defense, and mobile gaming organizations. It is considered to be an advanced cluster of Lazarus Group's Manuscrypt (a.k.a. NukeSped) malware family.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1005
Data from Local System

ThreatNeedle can collect data and files from a compromised host.

T1027.011
Fileless Storage

ThreatNeedle can save its configuration data as a RC4-encrypted Registry key under `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`.

T1027.013
Encrypted/Encoded File

ThreatNeedle has been compressed and obfuscated using RC4, AES, or XOR.

T1027.015
Compression

ThreatNeedle has been compressed and obfuscated.

T1036.005
Match Legitimate Resource Name or Location

ThreatNeedle chooses its payload creation path from a randomly selected service name from netsvc.

T1082
System Information Discovery

ThreatNeedle can collect system profile information from a compromised host.

T1083
File and Directory Discovery

ThreatNeedle can obtain file and directory information.

T1105
Ingress Tool Transfer

ThreatNeedle can download additional tools to enable lateral movement.

T1112
Modify Registry

ThreatNeedle can modify the Registry to save its configuration data as the following RC4-encrypted Registry key: `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`.

T1140
Deobfuscate/Decode Files or Information

ThreatNeedle can decrypt its payload using RC4, AES, or one-byte XORing.

T1204.002
Malicious File

ThreatNeedle relies on a victim to click on a malicious document for initial execution.

T1543.003
Windows Service

ThreatNeedle can run in memory and register its payload as a Windows service.

T1547.001
Registry Run Keys / Startup Folder

ThreatNeedle can be loaded into the Startup folder (`%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\OneDrives.lnk`) as a Shortcut file for persistence.

T1566.001
Spearphishing Attachment

ThreatNeedle has been distributed via a malicious Word document within a spearphishing email.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky ThreatNeedle Feb 2021 Open source
    Vyacheslav Kopeytsev and Seongsu Park. (2021, February 25). Lazarus targets defense industry with ThreatNeedle. Retrieved October 27, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.