MgBot

S1146

Malware.View on attack.mitre.org

About this malware

MgBot is a modular malware framework exclusively associated with Daggerfly operations since at least 2012. MgBot was developed in C++ and features a module design with multiple available plugins that have been under active development through 2024.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1003
OS Credential Dumping

MgBot includes modules for dumping and capturing credentials from process memory.

T1005
Data from Local System

MgBot includes modules for collecting files from local systems based on a given set of properties and filenames.

T1018
Remote System Discovery

MgBot includes modules for performing ARP scans of local connected systems.

T1025
Data from Removable Media

MgBot includes modules capable of gathering information from USB thumb drives and CD-ROMs on the victim machine given a list of provided criteria.

T1033
System Owner/User Discovery

MgBot includes modules for identifying local users and administrators on victim machines.

T1046
Network Service Discovery

MgBot includes modules for performing HTTP and server service scans.

T1056.001
Keylogging

MgBot includes keylogger payloads focused on the QQ chat application.

T1057
Process Discovery

MgBot includes a module for establishing a process watchdog for itself, identifying if the MgBot process is still running.

T1087.001
Local Account

MgBot includes modules for identifying local administrator accounts on victim systems.

T1087.002
Domain Account

MgBot includes modules for collecting information on Active Directory domain accounts.

T1115
Clipboard Data

MgBot can capture clipboard data.

T1123
Audio Capture

MgBot can capture input and output audio streams from infected devices.

T1213.006
Databases

MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices.

T1482
Domain Trust Discovery

MgBot includes modules for collecting information on local domain users and permissions.

T1539
Steal Web Session Cookie

MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. ESET EvasivePanda 2023 Open source
    Facundo Muñoz. (2023, April 26). Evasive Panda APT group delivers malware via updates for popular Chinese software. Retrieved July 25, 2024.
  2. Symantec Daggerfly 2024 Open source
    Threat Hunter Team. (2024, July 23). Daggerfly: Espionage Group Makes Major Update to Toolset. Retrieved July 25, 2024.
  3. Szappanos MgBot 2014 Open source
    Gabor Szappanos. (2014, February 3). Needle in a haystack. Retrieved July 25, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.