ATT&CKSoftwareAction RAT

Action RAT

S1028

Malware.View on attack.mitre.org

About this malware

Action RAT is a remote access tool written in Delphi that has been used by SideCopy since at least December 2021 against Indian and Afghani government personnel.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1005
Data from Local System

Action RAT can collect local data from an infected machine.

T1016
System Network Configuration Discovery

Action RAT has the ability to collect the MAC address of an infected host.

T1027
Obfuscated Files or Information

Action RAT's commands, strings, and domains can be Base64 encoded within the payload.

T1033
System Owner/User Discovery

Action RAT has the ability to collect the username from an infected host.

T1047
Windows Management Instrumentation

Action RAT can use WMI to gather AV products installed on an infected host.

T1059.003
Windows Command Shell

Action RAT can use `cmd.exe` to execute commands on an infected host.

T1071.001
Web Protocols

Action RAT can use HTTP to communicate with C2 servers.

T1082
System Information Discovery

Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host.

T1083
File and Directory Discovery

Action RAT has the ability to collect drive and file information on an infected machine.

T1105
Ingress Tool Transfer

Action RAT has the ability to download additional payloads onto an infected machine.

T1140
Deobfuscate/Decode Files or Information

Action RAT can use Base64 to decode actor-controlled C2 server communications.

T1518.001
Security Software Discovery

Action RAT can identify AV products on an infected host using the following command: `cmd.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`.

Groups that use it1

Campaigns0

None recorded.

References1

  1. MalwareBytes SideCopy Dec 2021 Open source
    Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.