Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareShimRat | ShimRat has the capability to upload collected files to a C2. |
| T1008 Fallback Channels |
MalwareShimRat | ShimRat has used a secondary C2 location if the first was unavailable. |
| T1016 System Network Configuration Discovery |
ToolShimRatReporter | ShimRatReporter gathered the local proxy, domain, IP, routing tables, mac address, gateway, DNS servers, and DHCP status information from an infected host. |
| T1020 Automated Exfiltration |
ToolShimRatReporter | ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2. |
| T1027 Obfuscated Files or Information |
ToolShimRatReporter | ShimRatReporter encrypted gathered information with a combination of shifting and XOR using a static key. |
| T1027.002 Software Packing |
MalwareShimRat | ShimRat's loader has been packed with the compressed ShimRat core DLL and the legitimate DLL for it to hijack. |
| T1027.013 Encrypted/Encoded File |
GroupMofang | Mofang has encrypted payloads before they are downloaded to victims. |
| T1027.015 Compression |
GroupMofang | Mofang has compressed the ShimRat executable within malicious email attachments. |
| T1027.015 Compression |
MalwareShimRat | ShimRat has been delivered as a package that includes compressed DLL and shellcode payloads within a .dat file. |
| T1029 Scheduled Transfer |
MalwareShimRat | ShimRat can sleep when instructed to do so by the C2. |
| T1036.004 Masquerade Task or Service |
MalwareShimRat | ShimRat can impersonate Windows services and antivirus products to avoid detection on compromised systems. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolShimRatReporter | ShimRatReporter spoofed itself as |
| T1041 Exfiltration Over C2 Channel |
ToolShimRatReporter | ShimRatReporter sent generated reports to the C2 via HTTP POST requests. |
| T1049 System Network Connections Discovery |
ToolShimRatReporter | ShimRatReporter used the Windows function |
| T1057 Process Discovery |
ToolShimRatReporter | ShimRatReporter listed all running processes on the machine. |
| T1059.003 Windows Command Shell |
MalwareShimRat | ShimRat can be issued a command shell function from the C2. |
| T1069 Permission Groups Discovery |
ToolShimRatReporter | ShimRatReporter gathered the local privileges for the infected host. |
| T1070.004 File Deletion |
MalwareShimRat | ShimRat can uninstall itself from compromised hosts, as well create and modify directories, delete, move, copy, and rename files. |
| T1071.001 Web Protocols |
MalwareShimRat | ShimRat communicated over HTTP and HTTPS with C2 servers. |
| T1071.001 Web Protocols |
ToolShimRatReporter | ShimRatReporter communicated over HTTP with preconfigured C2 servers. |
| T1082 System Information Discovery |
ToolShimRatReporter | ShimRatReporter gathered the operating system name and specific Windows version of an infected machine. |
| T1083 File and Directory Discovery |
MalwareShimRat | ShimRat can list directories. |
| T1087 Account Discovery |
ToolShimRatReporter | ShimRatReporter listed all non-privileged and privileged accounts available on the machine. |
| T1090.002 External Proxy |
MalwareShimRat | ShimRat can use pre-configured HTTP proxies. |
| T1105 Ingress Tool Transfer |
MalwareShimRat | ShimRat can download additional files. |
| T1105 Ingress Tool Transfer |
ToolShimRatReporter | ShimRatReporter had the ability to download additional payloads. |
| T1106 Native API |
ToolShimRatReporter | ShimRatReporter used several Windows API functions to gather information from the infected system. |
| T1106 Native API |
MalwareShimRat | ShimRat has used Windows API functions to install the service and shim. |
| T1112 Modify Registry |
MalwareShimRat | ShimRat has registered two registry keys for shim databases. |
| T1119 Automated Collection |
ToolShimRatReporter | ShimRatReporter gathered information automatically, without instruction from a C2, related to the user and host machine that is compiled into a report and sent to the operators. |
| T1135 Network Share Discovery |
MalwareShimRat | ShimRat can enumerate connected drives for infected host machines. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareShimRat | ShimRat has decompressed its core DLL using shellcode once an impersonated antivirus component was running on a system. |
| T1204.001 Malicious Link |
GroupMofang | Mofang's spearphishing emails required a user to click the link to connect to a compromised website. |
| T1204.002 Malicious File |
GroupMofang | Mofang's malicious spearphishing attachments required a user to open the file after receiving. |
| T1518 Software Discovery |
ToolShimRatReporter | ShimRatReporter gathered a list of installed software on the infected host. |
| T1543.003 Windows Service |
MalwareShimRat | ShimRat has installed a Windows service to maintain persistence on victim machines. |
| T1546.011 Application Shimming |
MalwareShimRat | ShimRat has installed shim databases in the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareShimRat | ShimRat has installed a registry based start-up key |
| T1548.002 Bypass User Account Control |
MalwareShimRat | ShimRat has hijacked the cryptbase.dll within migwiz.exe to escalate privileges. This prevented the User Access Control window from appearing. |
| T1560 Archive Collected Data |
ToolShimRatReporter | ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2. |
| T1566.001 Spearphishing Attachment |
GroupMofang | Mofang delivered spearphishing emails with malicious documents, PDFs, or Excel files attached. |
| T1566.002 Spearphishing Link |
GroupMofang | Mofang delivered spearphishing emails with malicious links included. |
| T1574 Hijack Execution Flow |
MalwareShimRat | ShimRat can hijack the cryptbase.dll within migwiz.exe to escalate privileges and bypass UAC controls. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.