Malware.View on attack.mitre.org
ROAMINGHOUSE is a dropper malware used by MirrorFace to extract and execute embedded payloads including UPPERCUT components.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
ROAMINGHOUSE can embed a ZIP file containing UPPERCUT components into three base64 encoded parts. |
| T1047 Windows Management Instrumentation |
ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading. |
| T1137.001 Office Template Macros |
ROAMINGHOUSE has been loaded as a Word Template file when victims opened a decoy document placed in `%APPDATA%\Microsoft\Templates` alongside a ROAMINGHOUSE macro. |
| T1140 Deobfuscate/Decode Files or Information |
ROAMINGHOUSE can decode and drop a malicious ZIP file prior to execution. |
| T1204.001 Malicious Link |
ROAMINGHOUSE has been executed through luring victims into clicking links to download malicious ZIP files. |
| T1204.002 Malicious File |
During Operation AkaiRyū, MirrorFace used malicious files to drop ROAMINGHOUSE. |
| T1480 Execution Guardrails |
ROAMINGHOUSE can change its execution method to create a batch file in the startup folder that executes a legitimate executable if a McAfee product is detected. |
| T1497.002 User Activity Based Checks |
ROAMINGHOUSE can check for specific mouse movements and user activity before initiating malicious activity. |
| T1518.001 Security Software Discovery |
ROAMINGHOUSE can identify McAfee applications on compromised hosts and change its execution method if one is detected. |
| T1566.002 Spearphishing Link |
ROAMINGHOUSE has been distributed through phishing emails containing malicious OneDrive links. |
| T1574.001 DLL |
ROAMINGHOUSE can use a legitimate EXE to sideload a malicious DLL named JSFC.dll. ROAMINGHOUSE has also used ScnCfg32.exe to sideload vsodscpl.dll to enable UPPERCUT execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.