Ferocious

S0679

Malware.View on attack.mitre.org

About this malware

Ferocious is a first stage implant composed of VBS and PowerShell scripts that has been used by WIRTE since at least 2021.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1059.001
PowerShell

Ferocious can use PowerShell scripts for execution.

T1059.005
Visual Basic

Ferocious has the ability to use Visual Basic scripts for execution.

T1070.004
File Deletion

Ferocious can delete files from a compromised host.

T1082
System Information Discovery

Ferocious can use GET.WORKSPACE in Microsoft Excel to determine the OS version of the compromised host.

T1112
Modify Registry

Ferocious has the ability to add a Class ID in the current user Registry hive to enable persistence mechanisms.

T1120
Peripheral Device Discovery

Ferocious can run GET.WORKSPACE in Microsoft Excel to check if a mouse is present.

T1497.001
System Checks

Ferocious can run anti-sandbox checks using the Microsoft Excel 4.0 function GET.WORKSPACE to determine the OS version, if there is a mouse present, and if the host is capable of playing sounds.

T1518.001
Security Software Discovery

Ferocious has checked for AV software as part of its persistence process.

T1546.015
Component Object Model Hijacking

Ferocious can use COM hijacking to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky WIRTE November 2021 Open source
    Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.