Samurai

S1099

Malware.View on attack.mitre.org

About this malware

Samurai is a passive backdoor that has been used by ToddyCat since at least 2020. Samurai allows arbitrary C# code execution and is used with multiple modules for remote administration and lateral movement.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1005
Data from Local System

Samurai can leverage an exfiltration module to download arbitrary files from compromised machines.

T1012
Query Registry

Samurai can query `SOFTWARE\Microsoft\.NETFramework\policy\v2.0` for discovery.

T1027
Obfuscated Files or Information

Samurai can encrypt the names of requested APIs.

T1027.004
Compile After Delivery

Samurai can compile and execute downloaded modules at runtime.

T1027.007
Dynamic API Resolution

Samurai can encrypt API name strings with an XOR-based algorithm.

T1027.015
Compression

Samurai can deliver its final payload as a compressed, encrypted and base64-encoded blob.

T1036.005
Match Legitimate Resource Name or Location

Samurai has created the directory `%COMMONPROGRAMFILES%\Microsoft Shared\wmi\` to contain DLLs for loading successive stages.

T1059.003
Windows Command Shell

Samurai can use a remote command module for execution via the Windows command line.

T1071.001
Web Protocols

Samurai can use a .NET HTTPListener class to receive and handle HTTP POST requests.

T1083
File and Directory Discovery

Samurai can use a specific module for file enumeration.

T1090
Proxy

Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module.

T1095
Non-Application Layer Protocol

Samurai can use a proxy module to forward TCP packets to external hosts.

T1105
Ingress Tool Transfer

Samurai has been used to deploy other malware including Ninja.

T1106
Native API

Samurai has the ability to call Windows APIs.

T1112
Modify Registry

The Samurai loader component can create multiple Registry keys to force the svchost.exe process to load the final backdoor.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky ToddyCat June 2022 Open source
    Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.