ATT&CKReferencesNSA/FBI Drovorub August 2020

NSA/FBI Drovorub August 2020

NSA/FBI. (2020, August). Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware. Retrieved August 25, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareDrovorub

Drovorub can transfer files from the victim machine.

T1014
Rootkit
MalwareDrovorub

Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view.

T1027
Obfuscated Files or Information
MalwareDrovorub

Drovorub has used XOR encrypted payloads in WebSocket client to server messages.

T1041
Exfiltration Over C2 Channel
MalwareDrovorub

Drovorub can exfiltrate files over C2 infrastructure.

T1059.004
Unix Shell
MalwareDrovorub

Drovorub can execute arbitrary commands as root on a compromised system.

T1070.004
File Deletion
MalwareDrovorub

Drovorub can delete specific files from a compromised host.

T1071.001
Web Protocols
MalwareDrovorub

Drovorub can use the WebSocket protocol and has initiated communication with C2 servers with an HTTP Upgrade request.

T1090.001
Internal Proxy
MalwareDrovorub

Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network.

T1095
Non-Application Layer Protocol
MalwareDrovorub

Drovorub can use TCP to communicate between its agent and client modules.

T1105
Ingress Tool Transfer
MalwareDrovorub

Drovorub can download files to a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareDrovorub

Drovorub has de-obsfuscated XOR encrypted payloads in WebSocket messages.

T1547.006
Kernel Modules and Extensions
MalwareDrovorub

Drovorub can use kernel modules to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.