Sardonic

S1085

Malware.View on attack.mitre.org

About this malware

Sardonic is a backdoor written in C and C++ that is known to be used by FIN8, as early as August 2021 to target a financial institution in the United States. Sardonic has a plugin system that can load specially made DLLs and execute their functions.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1005
Data from Local System

Sardonic has the ability to collect data from a compromised machine to deliver to the attacker.

T1007
System Service Discovery

Sardonic has the ability to execute the `net start` command.

T1016
System Network Configuration Discovery

Sardonic has the ability to execute the `ipconfig` command.

T1027
Obfuscated Files or Information

Sardonic can use certain ConfuserEx features for obfuscation and can be encoded in a base64 string.

T1027.010
Command Obfuscation

Sardonic PowerShell scripts can be encrypted with RC4 and compressed using Gzip.

T1047
Windows Management Instrumentation

Sardonic can use WMI to execute PowerShell commands on a compromised machine.

T1049
System Network Connections Discovery

Sardonic has the ability to execute the `netstat` command.

T1055.004
Asynchronous Procedure Call

Sardonic can use the `QueueUserAPC` API to execute shellcode on a compromised machine.

T1057
Process Discovery

Sardonic has the ability to execute the `tasklist` command.

T1059.001
PowerShell

Sardonic has the ability to execute PowerShell commands on a compromised machine.

T1059.003
Windows Command Shell

Sardonic has the ability to run `cmd.exe` or other interactive processes on a compromised computer.

T1070
Indicator Removal

Sardonic has the ability to delete created WMI objects to evade detections.

T1082
System Information Discovery

Sardonic has the ability to collect the computer name, and CPU manufacturer name from a compromised machine. Sardonic also has the ability to execute the `ver` and `systeminfo` commands.

T1095
Non-Application Layer Protocol

Sardonic can communicate with actor-controlled C2 servers by using a custom little-endian binary protocol.

T1105
Ingress Tool Transfer

Sardonic has the ability to upload additional malicious files to a compromised machine.

View all 25 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Bitdefender Sardonic Aug 2021 Open source
    Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.
  2. Symantec FIN8 Jul 2023 Open source
    Symantec Threat Hunter Team. (2023, July 18). FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware. Retrieved August 9, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.