Malware.View on attack.mitre.org
CLAIMLOADER is a malware variant that frequently accompanies legitimate executables that are used for DLL side-loading known to be leveraged by Mustang Panda and was first observed utilized in 2021.
| Technique | Procedure example |
|---|---|
| T1027.007 Dynamic API Resolution |
CLAIMLOADER has utilized XOR-encrypted API names and native APIs of `LdrLoadDll()` and `LderGetProcedureAddress()` to resolve imports dynamically. |
| T1036.005 Match Legitimate Resource Name or Location |
CLAIMLOADER has imitated legitimate software directories through the creation and storage of the EXE and DLL in `C:\ProgramData\` and the use of legitimate looking names of software. |
| T1053.005 Scheduled Task |
CLAIMLOADER has created scheduled tasks that execute the loader every five(5) minutes using `schtasks /F /Create /TN \"<fake_software_name>\" /SC minute /MO 5 /TR |
| T1106 Native API |
CLAIMLOADER has used various Windows API calls during execution, when establishing persistence and defense evasion. CLAIMLOADER has also leveraged the legitimate API functions to run its shellcode through the callback function, including `GetDC()` and `EnumFontsW()`. CLAIMLOADER established persistence by utilizing the API `SHSetValue()`. CLAIMLOADER has utilized APIs with callback functions such as `EnumpropsExW`, `EnumSystemLanguageGroupsA`, and `EnumCalendarInfoExW`. |
| T1140 Deobfuscate/Decode Files or Information |
CLAIMLOADER has decoded its payload prior to execution. |
| T1204.002 Malicious File |
CLAIMLOADER has used tailored decoy documents as part of the installation routine to entice users to open attachments. |
| T1480.002 Mutual Exclusion |
CLAIMLOADER has created hardcoded mutex to ensure only a single instance of the malware is running. |
| T1547.001 Registry Run Keys / Startup Folder |
CLAIMLOADER has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1559.001 Component Object Model |
CLAIMLOADER has leveraged Component Object Model (COM) objects to create a scheduled task using `ITaskService` interface. |
| T1564.001 Hidden Files and Directories |
CLAIMLOADER has modified file attributes to remain hidden to a standard user. |
| T1574.001 DLL |
CLAIMLOADER has used a legitimately signed executable to execute a malicious payload within a DLL file. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.