ATT&CKReferencesKaspersky TajMahal April 2019

Kaspersky TajMahal April 2019

GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareTajMahal

TajMahal has the ability to steal documents from the local system including the print spooler queue.

T1016
System Network Configuration Discovery
MalwareTajMahal

TajMahal has the ability to identify the MAC address on an infected host.

T1020
Automated Exfiltration
MalwareTajMahal

TajMahal has the ability to manage an automated queue of egress files and commands sent to its C2.

T1025
Data from Removable Media
MalwareTajMahal

TajMahal has the ability to steal written CD images and files of interest from previously connected removable drives when they become available again.

T1027
Obfuscated Files or Information
MalwareTajMahal

TajMahal has used an encrypted Virtual File System to store plugins.

T1041
Exfiltration Over C2 Channel
MalwareTajMahal

TajMahal has the ability to send collected files over its C2.

T1055.001
Dynamic-link Library Injection
MalwareTajMahal

TajMahal has the ability to inject DLLs for malicious plugins into running processes.

T1056.001
Keylogging
MalwareTajMahal

TajMahal has the ability to capture keystrokes on an infected host.

T1057
Process Discovery
MalwareTajMahal

TajMahal has the ability to identify running processes and associated plugins on an infected host.

T1082
System Information Discovery
MalwareTajMahal

TajMahal has the ability to identify hardware information, the computer name, and OS information on an infected host.

T1083
File and Directory Discovery
MalwareTajMahal

TajMahal has the ability to index files from drives, user profiles, and removable drives.

T1112
Modify Registry
MalwareTajMahal

TajMahal can set the KeepPrintedJobs attribute for configured printers in SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Print\\Printers to enable document stealing.

T1113
Screen Capture
MalwareTajMahal

TajMahal has the ability to take screenshots on an infected host including capturing content from windows of instant messaging applications.

T1115
Clipboard Data
MalwareTajMahal

TajMahal has the ability to steal data from the clipboard of an infected host.

T1119
Automated Collection
MalwareTajMahal

TajMahal has the ability to index and compress files into a send queue for exfiltration.

T1120
Peripheral Device Discovery
MalwareTajMahal

TajMahal has the ability to identify connected Apple devices.

T1123
Audio Capture
MalwareTajMahal

TajMahal has the ability to capture VoiceIP application audio on an infected host.

T1124
System Time Discovery
MalwareTajMahal

TajMahal has the ability to determine local time on a compromised host.

T1125
Video Capture
MalwareTajMahal

TajMahal has the ability to capture webcam video.

T1129
Shared Modules
MalwareTajMahal

TajMahal has the ability to inject the LoadLibrary call template DLL into running processes.

T1518
Software Discovery
MalwareTajMahal

TajMahal has the ability to identify the Internet Explorer (IE) version on an infected host.

T1518.001
Security Software Discovery
MalwareTajMahal

TajMahal has the ability to identify which anti-virus products, firewalls, and anti-spyware products are in use.

T1539
Steal Web Session Cookie
MalwareTajMahal

TajMahal has the ability to steal web session cookies from Internet Explorer, Netscape Navigator, FireFox and RealNetworks applications.

T1560.002
Archive via Library
MalwareTajMahal

TajMahal has the ability to use the open source libraries XZip/Xunzip and zlib to compress files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.