Malware.View on attack.mitre.org
CHIMNEYSWEEP is a backdoor malware that was deployed during HomeLand Justice along with ROADSWEEP ransomware, and has been used to target Farsi and Arabic speakers since at least 2012.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
CHIMNEYSWEEP can collect files from compromised hosts. |
| T1027 Obfuscated Files or Information |
CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key. |
| T1027.001 Binary Padding |
The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size. |
| T1027.007 Dynamic API Resolution |
CHIMNEYSWEEP can use `LoadLibrary` and `GetProcAddress` to resolve Windows API function strings at run time. |
| T1027.009 Embedded Payloads |
CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation. |
| T1033 System Owner/User Discovery |
CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure. |
| T1041 Exfiltration Over C2 Channel |
CHIMNEYSWEEP can upload collected files to the command-and-control server. |
| T1053.005 Scheduled Task |
CHIMNEYSWEEP can use the Windows `SilentCleanup` scheduled task to enable payload execution. |
| T1056.001 Keylogging |
CHIMNEYSWEEP has the ability to support keylogging. |
| T1057 Process Discovery |
CHIMNEYSWEEP can check if a process name contains “creensaver.” |
| T1059.001 PowerShell |
CHIMNEYSWEEP can invoke the PowerShell command `[Reflection.Assembly]::LoadFile(\"%s\")\n$i=\"\"\n$r=[%s]::%s(\"%s\",[ref] $i)\necho $r,$i\n` to execute secondary payloads. |
| T1059.005 Visual Basic |
CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts. |
| T1070.006 Timestomp |
CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021. |
| T1071.001 Web Protocols |
CHIMNEYSWEEP can send `HTTP GET` requests to C2. |
| T1074.001 Local Data Staging |
CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.