Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareOkrum | Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests. |
| T1001.003 Protocol or Service Impersonation |
MalwareOkrum | Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests. |
| T1003.001 LSASS Memory |
MalwareOkrum | Okrum was seen using MimikatzLite to perform credential dumping. |
| T1003.005 Cached Domain Credentials |
MalwareOkrum | Okrum was seen using modified Quarks PwDump to perform credential dumping. |
| T1016 System Network Configuration Discovery |
MalwareOkrum | Okrum can collect network information, including the host IP address, DNS, and proxy information. |
| T1027.003 Steganography |
MalwareOkrum | Okrum's payload is encrypted and embedded within its loader, or within a legitimate PNG file. |
| T1033 System Owner/User Discovery |
MalwareOkrum | Okrum can collect the victim username. |
| T1036.004 Masquerade Task or Service |
MalwareOkrum | Okrum can establish persistence by adding a new service NtmsSvc with the display name Removable Storage to masquerade as a legitimate Removable Storage Manager. |
| T1041 Exfiltration Over C2 Channel |
MalwareOkrum | Data exfiltration is done by Okrum using the already opened channel with the C2 server. |
| T1049 System Network Connections Discovery |
MalwareOkrum | Okrum was seen using NetSess to discover NetBIOS sessions. |
| T1053.005 Scheduled Task |
MalwareOkrum | Okrum's installer can attempt to achieve persistence by creating a scheduled task. |
| T1056.001 Keylogging |
MalwareOkrum | Okrum was seen using a keylogger tool to capture keystrokes. |
| T1059.003 Windows Command Shell |
MalwareOkrum | Okrum's backdoor has used cmd.exe to execute arbitrary commands as well as batch scripts to update itself to a newer version. |
| T1070.004 File Deletion |
MalwareOkrum | Okrum's backdoor deletes files after they have been successfully uploaded to C2 servers. |
| T1071.001 Web Protocols |
MalwareOkrum | Okrum uses HTTP for communication with its C2. |
| T1082 System Information Discovery |
MalwareOkrum | Okrum can collect computer name, locale information, and information about the OS and architecture. |
| T1083 File and Directory Discovery |
MalwareOkrum | Okrum has used DriveLetterView to enumerate drive information. |
| T1090.002 External Proxy |
MalwareOkrum | Okrum can identify proxy servers configured and used by the victim, and use it to make HTTP requests to C2 its server. |
| T1105 Ingress Tool Transfer |
MalwareOkrum | Okrum has built-in commands for uploading, downloading, and executing files to the system. |
| T1124 System Time Discovery |
MalwareOkrum | Okrum can obtain the date and time of the compromised system. |
| T1132.001 Standard Encoding |
MalwareOkrum | Okrum has used base64 to encode C2 communication. |
| T1134.001 Token Impersonation/Theft |
MalwareOkrum | Okrum can impersonate a logged-on user's security context using a call to the ImpersonateLoggedOnUser API. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOkrum | Okrum's loader can decrypt the backdoor code, embedded within the loader or within a legitimate PNG file. A custom XOR cipher or RC4 is used for decryption. |
| T1497.001 System Checks |
MalwareOkrum | Okrum's loader can check the amount of physical memory and terminates itself if the host has less than 1.5 Gigabytes of physical memory in total. |
| T1497.002 User Activity Based Checks |
MalwareOkrum | Okrum loader only executes the payload after the left mouse button has been pressed at least three times, in order to avoid being executed within virtualized or emulated environments. |
| T1497.003 Time Based Checks |
MalwareOkrum | Okrum's loader can detect presence of an emulator by using two calls to GetTickCount API, and checking whether the time has been accelerated. |
| T1543.003 Windows Service |
MalwareOkrum | To establish persistence, Okrum can install itself as a new service named NtmSsvc. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareOkrum | Okrum establishes persistence by creating a .lnk shortcut to itself in the Startup folder. |
| T1547.009 Shortcut Modification |
MalwareOkrum | Okrum can establish persistence by creating a .lnk shortcut to itself in the Startup folder. |
| T1560.001 Archive via Utility |
MalwareOkrum | Okrum was seen using a RAR archiver tool to compress/decompress data. |
| T1560.003 Archive via Custom Method |
MalwareOkrum | Okrum has used a custom implementation of AES encryption to encrypt collected data. |
| T1564.001 Hidden Files and Directories |
MalwareOkrum | Before exfiltration, Okrum's backdoor has used hidden files to store logs and outputs from backdoor commands. |
| T1569.002 Service Execution |
MalwareOkrum | Okrum's loader can create a new service named NtmsSvc to execute the payload. |
| T1573.001 Symmetric Cryptography |
MalwareOkrum | Okrum uses AES to encrypt network traffic. The key can be hardcoded or negotiated with the C2 server in the registration phase. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.