Woody RAT

S1065

Malware.View on attack.mitre.org

About this malware

Woody RAT is a remote access trojan (RAT) that has been used since at least August 2021 against Russian organizations.

Techniques used30

Procedure examples30

TechniqueProcedure example
T1005
Data from Local System

Woody RAT can collect information from a compromised host.

T1012
Query Registry

Woody RAT can search registry keys to identify antivirus programs on an compromised host.

T1016
System Network Configuration Discovery

Woody RAT can retrieve network interface and proxy information.

T1016.001
Internet Connection Discovery

Woody RAT can make `Ping` GET HTTP requests to its C2 server at regular intervals for network connectivity checks.

T1027.013
Encrypted/Encoded File

Woody RAT has used Base64 encoded strings and scripts.

T1033
System Owner/User Discovery

Woody RAT can retrieve a list of user accounts and usernames from an infected machine.

T1041
Exfiltration Over C2 Channel

Woody RAT can exfiltrate files from an infected machine to its C2 server.

T1055
Process Injection

Woody RAT can inject code into a targeted process by writing to the remote memory of an infected system and then create a remote thread.

T1055.012
Process Hollowing

Woody RAT can create a suspended notepad process and write shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`.

T1057
Process Discovery

Woody RAT can call `NtQuerySystemProcessInformation` with `SystemProcessInformation` to enumerate all running processes, including associated information such as PID, parent PID, image name, and owner.

T1059.001
PowerShell

Woody RAT can execute PowerShell commands and scripts with the use of .NET DLL, `WoodyPowerSession`.

T1059.003
Windows Command Shell

Woody RAT can execute commands using `cmd.exe`.

T1070.004
File Deletion

Woody RAT has the ability to delete itself from disk by creating a suspended notepad process and writing shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`.

T1071.001
Web Protocols

Woody RAT can communicate with its C2 server using HTTP requests.

T1082
System Information Discovery

Woody RAT can retrieve the following information from an infected machine: OS, architecture, computer name, OS build version, and environment variables.

View all 30 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. MalwareBytes WoodyRAT Aug 2022 Open source
    MalwareBytes Threat Intelligence Team. (2022, August 3). Woody RAT: A new feature-rich malware spotted in the wild. Retrieved December 6, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.