ATT&CKReferencesKaspersky Ferocious Kitten Jun 2021

Kaspersky Ferocious Kitten Jun 2021

GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMarkiRAT

MarkiRAT can upload data from the victim's machine to the C2 server.

T1033
System Owner/User Discovery
MalwareMarkiRAT

MarkiRAT can retrieve the victim’s username.

T1036.002
Right-to-Left Override
GroupFerocious Kitten

Ferocious Kitten has used right-to-left override to reverse executables’ names to make them appear to have different file extensions, rather than their real ones.

T1036.005
Match Legitimate Resource Name or Location
MalwareMarkiRAT

MarkiRAT can masquerade as update.exe and svehost.exe; it has also mimicked legitimate Telegram and Chrome files.

T1036.005
Match Legitimate Resource Name or Location
GroupFerocious Kitten

Ferocious Kitten has named malicious files update.exe and loaded them into the compromise host's “Public” folder.

T1041
Exfiltration Over C2 Channel
MalwareMarkiRAT

MarkiRAT can exfiltrate locally stored data via its C2.

T1056.001
Keylogging
MalwareMarkiRAT

MarkiRAT can capture all keystrokes on a compromised host.

T1057
Process Discovery
MalwareMarkiRAT

MarkiRAT can search for different processes on a system.

T1059.003
Windows Command Shell
MalwareMarkiRAT

MarkiRAT can utilize cmd.exe to execute commands in a victim's environment.

T1071.001
Web Protocols
MalwareMarkiRAT

MarkiRAT can initiate communication over HTTP/HTTPS for its C2 server.

T1074.001
Local Data Staging
MalwareMarkiRAT

MarkiRAT can store collected data locally in a created .nfo file.

T1082
System Information Discovery
MalwareMarkiRAT

MarkiRAT can obtain the computer name from a compromised host.

T1083
File and Directory Discovery
MalwareMarkiRAT

MarkiRAT can look for files carrying specific extensions such as: .rtf, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pps, .ppsx, .txt, .gpg, .pkr, .kdbx, .key, and .jpb.

T1105
Ingress Tool Transfer
MalwareMarkiRAT

MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin.

T1106
Native API
MalwareMarkiRAT

MarkiRAT can run the ShellExecuteW API via the Windows Command Shell.

T1113
Screen Capture
MalwareMarkiRAT

MarkiRAT can capture screenshots that are initially saved as ‘scr.jpg’.

T1115
Clipboard Data
MalwareMarkiRAT

MarkiRAT can capture clipboard content.

T1197
BITS Jobs
MalwareMarkiRAT

MarkiRAT can use BITS Utility to connect with the C2 server.

T1204.002
Malicious File
GroupFerocious Kitten

Ferocious Kitten has attempted to convince victims to enable malicious content within a spearphishing email by including an odd decoy message.

T1518
Software Discovery
MalwareMarkiRAT

MarkiRAT can check for the Telegram installation directory by enumerating the files on disk.

T1518.001
Security Software Discovery
MalwareMarkiRAT

MarkiRAT can check for running processes on the victim’s machine to look for Kaspersky and Bitdefender antivirus products.

T1547.001
Registry Run Keys / Startup Folder
MalwareMarkiRAT

MarkiRAT can drop its payload into the Startup directory to ensure it automatically runs when the compromised system is started.

T1547.009
Shortcut Modification
MalwareMarkiRAT

MarkiRAT can modify the shortcut that launches Telegram by replacing its path with the malicious payload to launch with the legitimate executable.

T1555.005
Password Managers
MalwareMarkiRAT

MarkiRAT can gather information from the Keepass password manager.

T1566.001
Spearphishing Attachment
GroupFerocious Kitten

Ferocious Kitten has conducted spearphishing campaigns containing malicious documents to lure victims to open the attachments.

T1583.001
Domains
GroupFerocious Kitten

Ferocious Kitten has acquired domains imitating legitimate sites.

T1588.002
Tool
GroupFerocious Kitten

Ferocious Kitten has obtained open source tools for its operations, including JsonCPP and Psiphon.

T1614.001
System Language Discovery
MalwareMarkiRAT

MarkiRAT can use the GetKeyboardLayout API to check if a compromised host's keyboard is set to Persian.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.