ATT&CKReferencesBitsight Latrodectus June 2024

Bitsight Latrodectus June 2024

Batista, J. (2024, June 17). Latrodectus, are you coming back?. Retrieved September 13, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareLatrodectus

Latrodectus can collect data from a compromised host using a stealer module.

T1016
System Network Configuration Discovery
MalwareLatrodectus

Latrodectus can discover the IP and MAC address of a targeted host.

T1027.013
Encrypted/Encoded File
MalwareLatrodectus

Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings.

T1041
Exfiltration Over C2 Channel
MalwareLatrodectus

Latrodectus can exfiltrate encrypted system information to the C2 server.

T1047
Windows Management Instrumentation
MalwareLatrodectus

Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files.

T1053.005
Scheduled Task
MalwareLatrodectus

Latrodectus can create scheduled tasks for persistence.

T1057
Process Discovery
MalwareLatrodectus

Latrodectus can enumerate running processes including process grandchildren on targeted hosts.

T1059.003
Windows Command Shell
MalwareLatrodectus

The Latrodectus command handler can use `cmdexe` to run multiple discovery commands.

T1059.007
JavaScript
MalwareLatrodectus

Latrodectus has used JavaScript files as part its infection chain during malicious spam
email campaigns.

T1069.002
Domain Groups
MalwareLatrodectus

Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`.

T1070.004
File Deletion
MalwareLatrodectus

Latrodectus has the ability to delete itself.

T1071.001
Web Protocols
MalwareLatrodectus

Latrodectus can send registration information to C2 via HTTP `POST`.

T1082
System Information Discovery
MalwareLatrodectus

Latrodectus can gather operating system information.

T1083
File and Directory Discovery
MalwareLatrodectus

Latrodectus can collect desktop filenames.

T1105
Ingress Tool Transfer
MalwareLatrodectus

Latrodectus can download and execute PEs, DLLs, and shellcode from C2.

T1106
Native API
MalwareLatrodectus

Latrodectus has used multiple Windows API post exploitation including `GetAdaptersInfo`, `CreateToolhelp32Snapshot`, and `CreateProcessW`.

T1135
Network Share Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares.

T1140
Deobfuscate/Decode Files or Information
MalwareLatrodectus

Latrodectus has the ability to deobfuscate encrypted strings.

T1482
Domain Trust Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c nltest /domain_trusts` to discover domain trusts.

T1497.001
System Checks
MalwareLatrodectus

Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address.

T1518.001
Security Software Discovery
MalwareLatrodectus

Latrodectus has the ability to identify installed antivirus products.

T1559.001
Component Object Model
MalwareLatrodectus

Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks.

T1573.001
Symmetric Cryptography
MalwareLatrodectus

Latrodectus can send RC4 encrypted data over C2 channels.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.