SVCReady

S1064

Malware.View on attack.mitre.org

About this malware

SVCReady is a loader that has been used since at least April 2022 in malicious spam campaigns. Security researchers have noted overlaps between TA551 activity and SVCReady distribution, including similarities in file names, lure images, and identical grammatical errors.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1005
Data from Local System

SVCReady can collect data from an infected host.

T1012
Query Registry

SVCReady can search for the `HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System` Registry key to gather system information.

T1027
Obfuscated Files or Information

SVCReady can encrypt victim data with an RC4 cipher.

T1033
System Owner/User Discovery

SVCReady can collect the username from an infected host.

T1036.004
Masquerade Task or Service

SVCReady has named a task `RecoveryExTask` as part of its persistence activity.

T1041
Exfiltration Over C2 Channel

SVCReady can send collected data in JSON format to its C2 server.

T1047
Windows Management Instrumentation

SVCReady can use `WMI` queries to detect the presence of a virtual machine environment.

T1053.005
Scheduled Task

SVCReady can create a scheduled task named `RecoveryExTask` to gain persistence.

T1057
Process Discovery

SVCReady can collect a list of running processes from an infected host.

T1059.005
Visual Basic

SVCReady has used VBA macros to execute shellcode.

T1071.001
Web Protocols

SVCReady can communicate with its C2 servers via HTTP.

T1082
System Information Discovery

SVCReady has the ability to collect information such as computer name, computer manufacturer, BIOS, operating system, and firmware, including through the use of `systeminfo.exe`.

T1105
Ingress Tool Transfer

SVCReady has the ability to download additional tools such as the RedLine Stealer to an infected host.

T1106
Native API

SVCReady can use Windows API calls to gather information from an infected host.

T1113
Screen Capture

SVCReady can take a screenshot from an infected host.

View all 24 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. HP SVCReady Jun 2022 Open source
    Schlapfer, Patrick. (2022, June 6). A New Loader Gets Ready. Retrieved December 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.