Malware.View on attack.mitre.org
Mongall is a backdoor that has been used since at least 2013, including by Aoqin Dragon.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Mongall has the ability to upload files from victim's machines. |
| T1027.002 Software Packing |
Mongall has been packed with Themida. |
| T1041 Exfiltration Over C2 Channel |
Mongall can upload files and information from a compromised host to its C2 server. |
| T1055.001 Dynamic-link Library Injection |
Mongall can inject a DLL into `rundll32.exe` for execution. |
| T1071.001 Web Protocols |
Mongall can use HTTP for C2 communication. |
| T1082 System Information Discovery |
Mongall can retrieve the hostname via `gethostbyname`. |
| T1105 Ingress Tool Transfer |
Mongall can download files to targeted systems. |
| T1120 Peripheral Device Discovery |
Mongall can identify removable media attached to compromised hosts. |
| T1132.001 Standard Encoding |
Mongall can use Base64 to encode information sent to its C2. |
| T1140 Deobfuscate/Decode Files or Information |
Mongall has the ability to decrypt its payload prior to execution. |
| T1204.002 Malicious File |
Mongall has relied on a user opening a malicious document for execution. |
| T1218.011 Rundll32 |
Mongall can use `rundll32.exe` for execution. |
| T1547.001 Registry Run Keys / Startup Folder |
Mongall can establish persistence with the auto start function including using the value `EverNoteTrayUService`. |
| T1573.001 Symmetric Cryptography |
Mongall has the ability to RC4 encrypt C2 communications. |
| T1680 Local Storage Discovery |
Mongall can identify drives on compromised hosts. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.