ATT&CKReferencesESET Attor Oct 2019

ESET Attor Oct 2019

Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples35

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareAttor

Attor can obtain application window titles and then determines which windows to perform Screen Capture on.

T1012
Query Registry
MalwareAttor

Attor has opened the registry and performed query searches.

T1020
Automated Exfiltration
MalwareAttor

Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server.

T1027.013
Encrypted/Encoded File
MalwareAttor

Strings in Attor's components are encrypted with a XOR cipher, using a hardcoded key and the configuration data, log files and plugins are encrypted using a hybrid encryption scheme of Blowfish-OFB combined with RSA.

T1036.004
Masquerade Task or Service
MalwareAttor

Attor's dispatcher disguises itself as a legitimate task (i.e., the task name and description appear legitimate).

T1037.001
Logon Script (Windows)
MalwareAttor

Attor's dispatcher can establish persistence via adding a Registry key with a logon script HKEY_CURRENT_USER\Environment "UserInitMprLogonScript" .

T1041
Exfiltration Over C2 Channel
MalwareAttor

Attor has exfiltrated data over the C2 channel.

T1053.005
Scheduled Task
MalwareAttor

Attor's installer plugin can schedule a new task that loads the dispatcher on boot/logon.

T1055
Process Injection
MalwareAttor

Attor's dispatcher can inject itself into running processes to gain higher privileges and to evade detection.

T1055.004
Asynchronous Procedure Call
MalwareAttor

Attor performs the injection by attaching its code into the APC queue using NtQueueApcThread API.

T1056.001
Keylogging
MalwareAttor

One of Attor's plugins can collect user credentials via capturing keystrokes and can capture keystrokes pressed within the window of the injected process.

T1070.004
File Deletion
MalwareAttor

Attor’s plugin deletes the collected files and log files after exfiltration.

T1070.006
Timestomp
MalwareAttor

Attor has manipulated the time of last access to files and registry keys after they have been created or modified.

T1071.002
File Transfer Protocols
MalwareAttor

Attor has used FTP protocol for C2 communication.

T1074.001
Local Data Staging
MalwareAttor

Attor has staged collected data in a central upload directory prior to exfiltration.

T1083
File and Directory Discovery
MalwareAttor

Attor has a plugin that enumerates files with specific extensions on all hard disk drives and stores file information in encrypted log files.

T1090.003
Multi-hop Proxy
MalwareAttor

Attor has used Tor for C2 communication.

T1105
Ingress Tool Transfer
MalwareAttor

Attor can download additional plugins, updates and other files.

T1106
Native API
MalwareAttor

Attor's dispatcher has used CreateProcessW API for execution.

T1112
Modify Registry
MalwareAttor

Attor's dispatcher can modify the Run registry key.

T1113
Screen Capture
MalwareAttor

Attor's has a plugin that captures screenshots of the target applications.

T1115
Clipboard Data
MalwareAttor

Attor has a plugin that collects data stored in the Windows clipboard by using the OpenClipboard and GetClipboardData APIs.

T1119
Automated Collection
MalwareAttor

Attor has automatically collected data about the compromised system.

T1120
Peripheral Device Discovery
MalwareAttor

Attor has a plugin that collects information about inserted storage devices, modems, and phone devices.

T1123
Audio Capture
MalwareAttor

Attor's has a plugin that is capable of recording audio using available input sound devices.

T1129
Shared Modules
MalwareAttor

Attor's dispatcher can execute additional plugins by loading the respective DLLs.

T1218.011
Rundll32
MalwareAttor

Attor's installer plugin can schedule rundll32.exe to load the dispatcher.

T1497.001
System Checks
MalwareAttor

Attor can detect whether it is executed in some virtualized or emulated environment by searching for specific artifacts, such as communication with I/O ports and using VM-specific instructions.

T1543.003
Windows Service
MalwareAttor

Attor's dispatcher can establish persistence by registering a new service.

T1560.003
Archive via Custom Method
MalwareAttor

Attor encrypts collected data with a custom implementation of Blowfish and RSA ciphers.

T1564.001
Hidden Files and Directories
MalwareAttor

Attor can set attributes of log files and directories to HIDDEN, SYSTEM, ARCHIVE, or a combination of those.

T1569.002
Service Execution
MalwareAttor

Attor's dispatcher can be executed as a service.

T1573.001
Symmetric Cryptography
MalwareAttor

Attor has encrypted data symmetrically using a randomly generated Blowfish (OFB) key which is encrypted with a public RSA key.

T1573.002
Asymmetric Cryptography
MalwareAttor

Attor's Blowfish key is encrypted with a public RSA key.

T1680
Local Storage Discovery
MalwareAttor

Attor monitors the free disk space on the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.