MagicRAT

S1182

Malware.View on attack.mitre.org

About this malware

MagicRAT is a remote access tool developed in C++ and exclusively used by the Lazarus Group threat actor in operations. MagicRAT allows for arbitrary command execution on victim machines and provides basic remote access functionality.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1016
System Network Configuration Discovery

MagicRAT collects system network information using commands such as `ipconfig /all`.

T1027.013
Encrypted/Encoded File

MagicRAT stores base64 encoded command and contorl URLs in a configuraiton file, with each URL prefixed with the value `LR02DPt22R`.

T1036.005
Match Legitimate Resource Name or Location

MagicRAT stores configuration data in files and file paths mimicking legitimate operating system resources.

T1036.008
Masquerade File Type

MagicRAT can download additional executable payloads that masquerade as GIF files.

T1041
Exfiltration Over C2 Channel

MagicRAT exfiltrates data via HTTP over existing command and control channels.

T1053.005
Scheduled Task

MagicRAT can persist via scheduled tasks.

T1059.003
Windows Command Shell

MagicRAT allows for the execution of arbitrary commands on the victim system.

T1070.004
File Deletion

MagicRAT can delete files on victim systems, including itself.

T1071.001
Web Protocols

MagicRAT uses HTTP POST communication for command and control.

T1082
System Information Discovery

MagicRAT collects basic system information from victim machines.

T1105
Ingress Tool Transfer

MagicRAT can import and execute additional payloads.

T1140
Deobfuscate/Decode Files or Information

MagicRAT stores command and control URLs using base64 encoding in the malware's configuration file.

T1547.001
Registry Run Keys / Startup Folder

MagicRAT can persist using malicious LNK objects in the victim machine Startup folder.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cisco MagicRAT 2022 Open source
    Asheer Malhotra, Vitor Ventura & Jungsoo An, Cisco Talos. (2022, September 7). MagicRAT: Lazarus’ latest gateway into victim networks. Retrieved December 30, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.