LitePower

S0680

Malware.View on attack.mitre.org

About this malware

LitePower is a downloader and second stage malware that has been used by WIRTE since at least 2021.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1012
Query Registry

LitePower can query the Registry for keys added to execute COM hijacking.

T1033
System Owner/User Discovery

LitePower can determine if the current user has admin privileges.

T1041
Exfiltration Over C2 Channel

LitePower can send collected data, including screenshots, over its C2 channel.

T1053.005
Scheduled Task

LitePower can create a scheduled task to enable persistence mechanisms.

T1059.001
PowerShell

LitePower can use a PowerShell script to execute commands.

T1071.001
Web Protocols

LitePower can use HTTP and HTTPS for C2 communications.

T1082
System Information Discovery

LitePower has the ability to enumerate the OS architecture.

T1105
Ingress Tool Transfer

LitePower has the ability to download payloads containing system commands to a compromised host.

T1106
Native API

LitePower can use various API calls.

T1113
Screen Capture

LitePower can take system screenshots and save them to `%AppData%`.

T1518.001
Security Software Discovery

LitePower can identify installed AV software.

T1680
Local Storage Discovery

LitePower has the ability to list local drives.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky WIRTE November 2021 Open source
    Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.