ATT&CKReferencesKaspersky ToddyCat Check Logs October 2023

Kaspersky ToddyCat Check Logs October 2023

Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples47

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupToddyCat

ToddyCat has run scripts to collect documents from targeted hosts.

T1005
Data from Local System
MalwareLoFiSe

LoFiSe can collect files of interest from targeted systems.

T1005
Data from Local System
MalwarePcexter

Pcexter can upload files from targeted systems.

T1018
Remote System Discovery
GroupToddyCat

ToddyCat has used `ping %REMOTE_HOST%` for post exploit discovery.

T1021.002
SMB/Windows Admin Shares
GroupToddyCat

ToddyCat has used locally mounted network shares for lateral movement through targated environments.

T1027.013
Encrypted/Encoded File
MalwareNinja

The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`.

T1027.015
Compression
MalwareNinja

Ninja has compressed its data with the LZSS algorithm.

T1036.005
Match Legitimate Resource Name or Location
MalwareNinja

Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll.

T1047
Windows Management Instrumentation
GroupToddyCat

ToddyCat has used WMI to execute scripts for post exploit document collection.

T1049
System Network Connections Discovery
GroupToddyCat

ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts.

T1053.005
Scheduled Task
GroupToddyCat

ToddyCat has used scheduled tasks to execute discovery commands and scripts for collection.

T1055
Process Injection
MalwareNinja

Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes.

T1057
Process Discovery
GroupToddyCat

ToddyCat has run `cmd /c start /b tasklist` to enumerate processes.

T1057
Process Discovery
MalwareNinja

Ninja can enumerate processes on a targeted host.

T1059.001
PowerShell
GroupToddyCat

ToddyCat has used Powershell scripts to perform post exploit collection.

T1059.003
Windows Command Shell
GroupToddyCat

ToddyCat has used .bat scripts and `cmd` for execution on compromised hosts.

T1069.002
Domain Groups
GroupToddyCat

ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines.

T1071.001
Web Protocols
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports.

T1074.001
Local Data Staging
MalwareLoFiSe

LoFiSe can save files to be evaluated for further exfiltration in the `C:\Programdata\Microsoft\` and `C:\windows\temp\` folders.

T1074.002
Remote Data Staging
GroupToddyCat

ToddyCat manually transferred collected files to an exfiltration host using xcopy.

T1078.002
Domain Accounts
GroupToddyCat

ToddyCat has used compromised domain admin credentials to mount local network shares.

T1082
System Information Discovery
MalwareNinja

Ninja can obtain the computer name and information on the OS from targeted hosts.

T1083
File and Directory Discovery
MalwarePcexter

Pcexter has the ability to search for files in specified directories.

T1083
File and Directory Discovery
MalwareLoFiSe

LoFiSe can monitor the file system to identify files less than 6.4 MB in size with file extensions including .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .tif, .odt, .ods, .odp, .eml, and .msg.

T1083
File and Directory Discovery
MalwareNinja

Ninja has the ability to enumerate directory content.

T1083
File and Directory Discovery
GroupToddyCat

ToddyCat has run scripts to enumerate recently modified documents having either a .pdf, .doc, .docx, .xls or .xlsx extension.

T1087.002
Domain Account
GroupToddyCat

ToddyCat has run `net user %USER% /dom` for account discovery.

T1090.001
Internal Proxy
MalwareNinja

Ninja can proxy C2 communications including to and from internal agents without internet connectivity.

T1095
Non-Application Layer Protocol
MalwareNinja

Ninja can forward TCP packets between the C2 and a remote host.

T1095
Non-Application Layer Protocol
GroupToddyCat

ToddyCat has used a passive backdoor that receives commands with UDP packets.

T1106
Native API
MalwareNinja

The Ninja loader can call Windows APIs for discovery, process injection, and payload decryption.

T1106
Native API
GroupToddyCat

ToddyCat has used `WinExec` to execute commands received from C2 on compromised hosts.

T1119
Automated Collection
MalwareLoFiSe

LoFiSe can collect all the files from the working directory every three hours and place them into a password-protected archive for further exfiltration.

T1140
Deobfuscate/Decode Files or Information
MalwareNinja

The Ninja loader component can decrypt and decompress the payload.

T1218.011
Rundll32
MalwareNinja

Ninja loader components can be executed through rundll32.exe.

T1518.001
Security Software Discovery
GroupToddyCat

ToddyCat can determine is Kaspersky software is running on an endpoint by running `cmd /c wmic process where name="avp.exe"`.

T1560
Archive Collected Data
MalwareLoFiSe

LoFiSe can collect files into password-protected ZIP-archives for exfiltration.

T1560.001
Archive via Utility
GroupToddyCat

ToddyCat has leveraged xcopy, 7zip, and RAR to stage and compress collected documents prior to exfiltration.

T1564.003
Hidden Window
GroupToddyCat

ToddyCat has hidden malicious scripts using `powershell.exe -windowstyle hidden`.

T1567.002
Exfiltration to Cloud Storage
MalwarePcexter

Pcexter can upload stolen files to OneDrive storage accounts via HTTP `POST`.

T1567.002
Exfiltration to Cloud Storage
GroupToddyCat

ToddyCat has used a DropBox uploader to exfiltrate stolen files.

T1574.001
DLL
MalwareLoFiSe

LoFiSe has been executed as a file named DsNcDiag.dll through side-loading.

T1574.001
DLL
MalwareNinja

Ninja loaders can be side-loaded with legitimate and signed executables including the VLC.exe media player.

T1574.001
DLL
MalwarePcexter

Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading.

T1680
Local Storage Discovery
MalwareNinja

Ninja can obtain information on physical drives from targeted hosts.

T1680
Local Storage Discovery
GroupToddyCat

ToddyCat has collected information on bootable drives including model, vendor, and serial numbers.

T1686
Disable or Modify System Firewall
GroupToddyCat

Prior to executing a backdoor ToddyCat has run `cmd /c start /b netsh advfirewall firewall add rule name="SGAccessInboundRule" dir=in protocol=udp action=allow localport=49683` to allow the targeted system to receive UDP packets on port 49683.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.