Malware.View on attack.mitre.org
WhisperGate is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and information technology organizations in Ukraine since at least January 2022.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage. |
| T1036 Masquerading |
WhisperGate has been disguised as a JPG extension to avoid detection as a malicious PE file. |
| T1055.012 Process Hollowing |
WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`. |
| T1059.001 PowerShell |
WhisperGate can use PowerShell to support multiple actions including execution and defense evasion. |
| T1059.003 Windows Command Shell |
WhisperGate can use `cmd.exe` to execute commands. |
| T1059.005 Visual Basic |
WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender. |
| T1070.004 File Deletion |
WhisperGate can delete tools from a compromised host after execution. |
| T1071.001 Web Protocols |
WhisperGate can make an HTTPS connection to download additional files. |
| T1083 File and Directory Discovery |
WhisperGate can locate files based on hardcoded file extensions. |
| T1102 Web Service |
WhisperGate can download additional payloads hosted on a Discord channel. |
| T1105 Ingress Tool Transfer |
WhisperGate can download additional stages of malware from a Discord CDN channel. |
| T1106 Native API |
WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls. |
| T1134.002 Create Process with Token |
The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`. |
| T1135 Network Share Discovery |
WhisperGate can enumerate connected remote logical drives. |
| T1140 Deobfuscate/Decode Files or Information |
WhisperGate can deobfuscate downloaded files stored in reverse byte order and decrypt embedded resources using multiple XOR operations. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.