Alex Turing, Hui Wang. (2021, April 28). RotaJakiro: A long live secret backdoor with 0 VT detection. Retrieved June 14, 2023.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts |
MalwareRotaJakiro | Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.conf` file in the `/etc/init/` folder. |
| T1041 Exfiltration Over C2 Channel |
MalwareRotaJakiro | RotaJakiro sends device and other collected data back to the C2 using the established C2 channels over TCP. |
| T1057 Process Discovery |
MalwareRotaJakiro | RotaJakiro can monitor the `/proc/[PID]` directory of known RotaJakiro processes as a part of its persistence when executing with non-root permissions. If the process is found dead, it resurrects the process. RotaJakiro processes can be matched to an associated Advisory Lock, in the `/proc/locks` folder, to ensure it doesn't spawn more than one process. |
| T1082 System Information Discovery |
MalwareRotaJakiro | RotaJakiro executes a set of commands to collect device information, including `uname`. Another example is the `cat /etc/*release | uniq` command used to collect the current OS distribution. |
| T1106 Native API |
MalwareRotaJakiro | When executing with non-root permissions, RotaJakiro uses the the `shmget` API to create shared memory between other known RotaJakiro processes. RotaJakiro also uses the `execvp` API to help its dead process "resurrect". |
| T1119 Automated Collection |
MalwareRotaJakiro | Depending on the Linux distribution, RotaJakiro executes a set of commands to collect device information and sends the collected information to the C2 server. |
| T1129 Shared Modules |
MalwareRotaJakiro | RotaJakiro uses dynamically linked shared libraries (`.so` files) to execute additional functionality using `dlopen()` and `dlsym()`. |
| T1132.001 Standard Encoding |
MalwareRotaJakiro | RotaJakiro uses ZLIB Compression to compresses data sent to the C2 server in the `payload` section network communication packet. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRotaJakiro | RotaJakiro uses the AES algorithm, bit shifts in a function called `rotate`, and an XOR cipher to decrypt resources required for persistence, process guarding, and file locking. It also performs this same function on encrypted stack strings and the `head` and `key` sections in the network packet structure used for C2 communications. |
| T1543.002 Systemd Service |
MalwareRotaJakiro | Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.service` file under the `/lib/systemd/system/` folder. |
| T1546.004 Unix Shell Configuration Modification |
MalwareRotaJakiro | When executing with non-root level permissions, RotaJakiro can install persistence by adding a command to the .bashrc file that executes a binary in the `${HOME}/.gvfsd/.profile/` folder. |
| T1547.013 XDG Autostart Entries |
MalwareRotaJakiro | When executing with user-level permissions, RotaJakiro can install persistence using a .desktop file under the `$HOME/.config/autostart/` folder. |
| T1559 Inter-Process Communication |
MalwareRotaJakiro | When executing with non-root permissions, RotaJakiro uses the the `shmget API` to create shared memory between other known RotaJakiro processes. This allows processes to communicate with each other and share their PID. |
| T1573.001 Symmetric Cryptography |
MalwareRotaJakiro | RotaJakiro encrypts C2 communication using a combination of AES, XOR, ROTATE encryption, and ZLIB compression. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.