Flagpro

S0696

Malware.View on attack.mitre.org

About this malware

Flagpro is a Windows-based, first-stage downloader that has been used by BlackTech since at least October 2020. It has primarily been used against defense, media, and communications companies in Japan.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1005
Data from Local System

Flagpro can collect data from a compromised host, including Windows authentication information.

T1010
Application Window Discovery

Flagpro can check the name of the window displayed on the system.

T1016
System Network Configuration Discovery

Flagpro has been used to execute the ipconfig /all command on a victim system.

T1018
Remote System Discovery

Flagpro has been used to execute net view on a targeted system.

T1027
Obfuscated Files or Information

Flagpro has been delivered within ZIP or RAR password-protected archived files.

T1029
Scheduled Transfer

Flagpro has the ability to wait for a specified time interval between communicating with and executing commands from C2.

T1033
System Owner/User Discovery

Flagpro has been used to run the whoami command on the system.

T1036
Masquerading

Flagpro can download malicious files with a .tmp extension and append them with .exe prior to execution.

T1041
Exfiltration Over C2 Channel

Flagpro has exfiltrated data to the C2 server.

T1049
System Network Connections Discovery

Flagpro has been used to execute netstat -ano on a compromised host.

T1057
Process Discovery

Flagpro has been used to run the tasklist command on a compromised system.

T1059.003
Windows Command Shell

Flagpro can use `cmd.exe` to execute commands received from C2.

T1059.005
Visual Basic

Flagpro can execute malicious VBA macros embedded in .xlsm files.

T1069.001
Local Groups

Flagpro has been used to execute the net localgroup administrators command on a targeted system.

T1070
Indicator Removal

Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections.

View all 24 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. NTT Security Flagpro new December 2021 Open source
    Hada, H. (2021, December 28). Flagpro The new malware used by BlackTech. Retrieved March 25, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.