ATT&CKSoftwareAuTo Stealer

AuTo Stealer

S1029

Malware.View on attack.mitre.org

About this malware

AuTo Stealer is malware written in C++ has been used by SideCopy since at least December 2021 to target government agencies and personnel in India and Afghanistan.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1005
Data from Local System

AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine.

T1033
System Owner/User Discovery

AuTo Stealer has the ability to collect the username from an infected host.

T1041
Exfiltration Over C2 Channel

AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP.

T1059.003
Windows Command Shell

AuTo Stealer can use `cmd.exe` to execute a created batch file.

T1071.001
Web Protocols

AuTo Stealer can use HTTP to communicate with its C2 servers.

T1074.001
Local Data Staging

AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration.

T1082
System Information Discovery

AuTo Stealer has the ability to collect the hostname and OS information from an infected host.

T1095
Non-Application Layer Protocol

AuTo Stealer can use TCP to communicate with command and control servers.

T1518.001
Security Software Discovery

AuTo Stealer has the ability to collect information about installed AV products from an infected host.

T1547.001
Registry Run Keys / Startup Folder

AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. MalwareBytes SideCopy Dec 2021 Open source
    Threat Intelligence Team. (2021, December 2). SideCopy APT: Connecting lures victims, payloads to infrastructure. Retrieved June 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.