Robert Falcone, Jeff White, and Peter Renals. (2021, November 7). Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer. Retrieved February 8, 2024.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareNGLite | NGLite identifies the victim system MAC and IPv4 addresses and uses these to establish a victim identifier. |
| T1033 System Owner/User Discovery |
MalwareNGLite | NGLite will run the |
| T1071.001 Web Protocols |
MalwareNGLite | NGLite will initially beacon out to the NKN network via an HTTP POST over TCP 30003. |
| T1090.003 Multi-hop Proxy |
MalwareNGLite | NGLite has abused NKN infrastructure for its C2 communication. |
| T1573.001 Symmetric Cryptography |
MalwareNGLite | NGLite will use an AES encrypted channel for command and control purposes, in one case using the key |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.