Malware.View on attack.mitre.org
StarProxy is custom malware used by Mustang Panda as a post-compromise tool, to enable proxying of traffic between the infected machine and other machines on the same network.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
StarProxy has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. StarProxy used FakeTLS to communicate with its C2 server. |
| T1059 Command and Scripting Interpreter |
StarProxy has used the command line for execution of commands. |
| T1090.001 Internal Proxy |
StarProxy has proxied traffic between infected devices and their C2 servers. |
| T1095 Non-Application Layer Protocol |
StarProxy has used TCP for C2 communications to target IPs or domains. StarProxy contained code to support both UDP and TCP connections. |
| T1106 Native API |
StarProxy has used native windows API calls such as `GetLocalTime()` to retrieve system data. |
| T1124 System Time Discovery |
StarProxy has utilized the windows API call `GetLocalTime()` to retrieve a SystemTime structure to generate a seed value. |
| T1140 Deobfuscate/Decode Files or Information |
StarProxy has decrypted network packets using a custom algorithm. |
| T1573.001 Symmetric Cryptography |
StarProxy has leveraged two 256-byte XOR keys to encrypt and decrypt network packets using a custom algorithm. |
| T1574.001 DLL |
StarProxy has been side-loaded by the legitimate, signed executable, IsoBurner.exe. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.