Malware.View on attack.mitre.org
NightClub is a modular implant written in C++ that has been used by MoustachedBouncer since at least 2014.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
NightClub can use a file monitor to steal specific files from targeted systems. |
| T1010 Application Window Discovery |
NightClub can use `GetForegroundWindow` to enumerate the active window. |
| T1027 Obfuscated Files or Information |
NightClub can obfuscate strings using the congruential generator `(LCG): staten+1 = (690069 × staten + 1) mod 232`. |
| T1036.004 Masquerade Task or Service |
NightClub has created a service named `WmdmPmSp` to spoof a Windows Media service. |
| T1036.005 Match Legitimate Resource Name or Location |
NightClub has chosen file names to appear legitimate including EsetUpdate-0117583943.exe for its dropper. |
| T1041 Exfiltration Over C2 Channel |
NightClub can use SMTP and DNS for file exfiltration and C2. |
| T1056.001 Keylogging |
NightClub can use a plugin for keylogging. |
| T1057 Process Discovery |
NightClub has the ability to use `GetWindowThreadProcessId` to identify the process behind a specified window. |
| T1070.006 Timestomp |
NightClub can modify the Creation, Access, and Write timestamps for malicious DLLs to match those of the genuine Windows DLL user32.dll. |
| T1071.003 Mail Protocols |
NightClub can use emails for C2 communications. |
| T1071.004 DNS |
NightClub can use a DNS tunneling plugin to exfiltrate data by adding it to the subdomain portion of a DNS request. |
| T1074.001 Local Data Staging |
NightClub has copied captured files and keystrokes to the `%TEMP%` directory of compromised hosts. |
| T1083 File and Directory Discovery |
NightClub can use a file monitor to identify .lnk, .doc, .docx, .xls, .xslx, and .pdf files. |
| T1105 Ingress Tool Transfer |
NightClub can load multiple additional plugins on an infected host. |
| T1106 Native API |
NightClub can use multiple native APIs including `GetKeyState`, `GetForegroundWindow`, `GetWindowThreadProcessId`, and `GetKeyboardLayout`. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.