Milan

S1015

Malware.View on attack.mitre.org

About this malware

Milan is a backdoor implant based on DanBot that was written in Visual C++ and .NET. Milan has been used by HEXANE since at least June 2020.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1005
Data from Local System

Milan can upload files from a compromised host.

T1012
Query Registry

Milan can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID.

T1016
System Network Configuration Discovery

Milan can run `C:\Windows\system32\cmd.exe /c cmd /c ipconfig /all 2>&1` to discover network settings.

T1027.013
Encrypted/Encoded File

Milan can encode files containing information about the targeted system.

T1033
System Owner/User Discovery

Milan can identify users registered to a targeted machine.

T1036
Masquerading

Milan has used an executable named `companycatalogue` to appear benign.

T1036.007
Double File Extension

Milan has used an executable named `companycatalog.exe.config` to appear benign.

T1053.005
Scheduled Task

Milan can establish persistence on a targeted host with scheduled tasks.

T1059.003
Windows Command Shell

Milan can use `cmd.exe` for discovery actions on a targeted system.

T1070.004
File Deletion

Milan can delete files via `C:\Windows\system32\cmd.exe /c ping 1.1.1.1 -n 1 -w 3000 > Nul & rmdir /s /q`.

T1071.001
Web Protocols

Milan can use HTTPS for communication with C2.

T1071.004
DNS

Milan has the ability to use DNS for C2 communications.

T1074.001
Local Data Staging

Milan has saved files prior to upload from a compromised host to folders beginning with the characters `a9850d2f`.

T1082
System Information Discovery

Milan can enumerate the targeted machine's name and GUID.

T1087.001
Local Account

Milan has run `C:\Windows\system32\cmd.exe /c cmd /c dir c:\users\ /s 2>&1` to discover local accounts.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. ClearSky Siamesekitten August 2021 Open source
    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.
  2. Kaspersky Lyceum October 2021 Open source
    Kayal, A. et al. (2021, October). LYCEUM REBORN: COUNTERINTELLIGENCE IN THE MIDDLE EAST. Retrieved June 14, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.