ccf32

S1043

Malware.View on attack.mitre.org

About this malware

ccf32 is data collection malware that has been used since at least February 2019, most notably during the FunnyDream campaign; there is also a similar x64 version.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1005
Data from Local System

ccf32 can collect files from a compromised host.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

ccf32 can upload collected data and files to an FTP server.

T1053.005
Scheduled Task

ccf32 can run on a daily basis using a scheduled task.

T1059.003
Windows Command Shell

ccf32 has used `cmd.exe` for archiving data and deleting files.

T1070.004
File Deletion

ccf32 can delete files and folders from compromised machines.

T1074.001
Local Data Staging

ccf32 can temporarily store files in a hidden directory on the local host.

T1074.002
Remote Data Staging

ccf32 has copied files to a remote machine infected with Chinoxy or another backdoor.

T1083
File and Directory Discovery

ccf32 can parse collected files to identify specific file extensions.

T1119
Automated Collection

ccf32 can be used to automatically collect files from a compromised host.

T1124
System Time Discovery

ccf32 can determine the local time on targeted machines.

T1560.001
Archive via Utility

ccf32 has used `xcopy \\<target_host>\c$\users\public\path.7z c:\users\public\bin\<target_host>.7z /H /Y` to archive collected files.

T1564.001
Hidden Files and Directories

ccf32 has created a hidden directory on targeted systems, naming it after the current local time (year, month, and day).

Groups that use it0

None recorded.

Campaigns1

References1

  1. Bitdefender FunnyDream Campaign November 2020 Open source
    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.