Malware.View on attack.mitre.org
Sagerunex is a malware family exclusively associated with Lotus Blossom operations, with variants existing since at least 2016. Variations of Sagerunex leverage non-traditional command and control mechanisms such as various web services.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Sagerunex will gather system information such as MAC and IP addresses. |
| T1027.002 Software Packing |
Sagerunex has used VMProtect to pack and obscure itself. |
| T1027.013 Encrypted/Encoded File |
Sagerunex can be passed a reference to an XOR-encrypted configuration file at runtime. |
| T1041 Exfiltration Over C2 Channel |
Sagerunex encrypts collected system data then exfiltrates via existing command and control channels. |
| T1055.001 Dynamic-link Library Injection |
Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory. |
| T1057 Process Discovery |
Sagerunex identifies the `explorer.exe` process on the executing system. |
| T1071.001 Web Protocols |
Sagerunex communicates via HTTPS, at times using a hard-coded User Agent of `Mozilla/5.0 (compatible; MSIE 7.0; Win32)`. |
| T1074.001 Local Data Staging |
Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution. |
| T1082 System Information Discovery |
Sagerunex gathers information from the infected system such as hostname. |
| T1090 Proxy |
Sagerunex uses several proxy configuration settings to ensure connectivity. |
| T1102.002 Bidirectional Communication |
Sagerunex has used virtual private servers (VPS) for command and control traffic as well as third-party cloud services in more recent variants. |
| T1102.003 One-Way Communication |
Sagerunex has used web services such as Twitter for command and control purposes. |
| T1106 Native API |
Sagerunex calls the `WaitForSingleObject` API function as part of time-check logic. |
| T1134 Access Token Manipulation |
Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread. |
| T1140 Deobfuscate/Decode Files or Information |
Sagerunex uses a custom decryption routine to unpack itself during installation. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.