ATT&CKReferencesPaloAlto UBoatRAT Nov 2017

PaloAlto UBoatRAT Nov 2017

Hayashi, K. (2017, November 28). UBoatRAT Navigates East Asia. Retrieved January 12, 2018.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareUBoatRAT

UBoatRAT can list running processes on the system.

T1059.003
Windows Command Shell
MalwareUBoatRAT

UBoatRAT can start a command shell.

T1071.001
Web Protocols
MalwareUBoatRAT

UBoatRAT has used HTTP for C2 communications.

T1102.002
Bidirectional Communication
MalwareUBoatRAT

UBoatRAT has used GitHub and a public blog service in Hong Kong for C2 communications.

T1105
Ingress Tool Transfer
MalwareUBoatRAT

UBoatRAT can upload and download files to the victim’s machine.

T1197
BITS Jobs
MalwareUBoatRAT

UBoatRAT takes advantage of the /SetNotifyCmdLine option in BITSAdmin to ensure it stays running on a system to maintain persistence.

T1497.001
System Checks
MalwareUBoatRAT

UBoatRAT checks for virtualization software such as VMWare, VirtualBox, or QEmu on the compromised machine.

T1573.001
Symmetric Cryptography
MalwareUBoatRAT

UBoatRAT encrypts instructions in its C2 network payloads using a simple XOR cipher.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.