KOPILUWAK

S1075

Malware.View on attack.mitre.org

About this malware

KOPILUWAK is a JavaScript-based reconnaissance tool that has been used for victim profiling and C2 since at least 2017.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1005
Data from Local System

KOPILUWAK can gather information from compromised hosts.

T1016
System Network Configuration Discovery

KOPILUWAK can use Arp to discover a target's network configuration setttings.

T1033
System Owner/User Discovery

KOPILUWAK can conduct basic network reconnaissance on the victim machine with `whoami`, to get user details.

T1041
Exfiltration Over C2 Channel

KOPILUWAK has exfiltrated collected data to its C2 via POST requests.

T1049
System Network Connections Discovery

KOPILUWAK can use netstat, Arp, and Net to discover current TCP connections.

T1057
Process Discovery

KOPILUWAK can enumerate current running processes on the targeted machine.

T1059.007
JavaScript

KOPILUWAK had used Javascript to perform its core functions.

T1071.001
Web Protocols

KOPILUWAK has used HTTP POST requests to send data to C2.

T1074.001
Local Data Staging

KOPILUWAK has piped the results from executed C2 commands to `%TEMP%\result2.dat` on the local machine.

T1135
Network Share Discovery

KOPILUWAK can use netstat and Net to discover network shares.

T1204.002
Malicious File

KOPILUWAK has gained execution through malicious attachments.

T1566.001
Spearphishing Attachment

KOPILUWAK has been delivered to victims as a malicious email attachment.

T1680
Local Storage Discovery

KOPILUWAK can discover logical drive information on compromised hosts.

Groups that use it1

Campaigns1

References1

  1. Mandiant Suspected Turla Campaign February 2023 Open source
    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.