ATT&CKReferencesScarlet Mimic Jan 2016

Scarlet Mimic Jan 2016

Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software4

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareFakeM

FakeM C2 traffic attempts to evade detection by resembling data generated by legitimate messenger applications, such as MSN and Yahoo! messengers. Additionally, some variants of FakeM use modified SSL code for communications back to C2 servers, making SSL decryption ineffective.

T1005
Data from Local System
MalwareMobileOrder

MobileOrder exfiltrates data collected from the victim mobile device.

T1036.002
Right-to-Left Override
GroupScarlet Mimic

Scarlet Mimic has used the left-to-right override character in self-extracting RAR archive spearphishing attachment file names.

T1041
Exfiltration Over C2 Channel
MalwarePsylo

Psylo exfiltrates data to its C2 server over the same protocol as C2 communications.

T1041
Exfiltration Over C2 Channel
MalwareCallMe

CallMe exfiltrates data to its C2 server over the same protocol as C2 communications.

T1041
Exfiltration Over C2 Channel
MalwareMobileOrder

MobileOrder exfiltrates data to its C2 server over the same protocol as C2 communications.

T1056.001
Keylogging
MalwareFakeM

FakeM contains a keylogger module.

T1057
Process Discovery
MalwareMobileOrder

MobileOrder has a command to upload information about all running processes to its C2 server.

T1059.004
Unix Shell
MalwareCallMe

CallMe has the capability to create a reverse shell on victims.

T1070.006
Timestomp
MalwarePsylo

Psylo has a command to conduct timestomping by setting a specified file’s timestamps to match those of a system file in the System32 directory.

T1071.001
Web Protocols
MalwarePsylo

Psylo uses HTTPS for C2.

T1082
System Information Discovery
MalwareMobileOrder

MobileOrder has a command to upload to its C2 server victim mobile device information, including IMEI, IMSI, SIM card serial number, phone number, Android version, and other information.

T1083
File and Directory Discovery
MalwarePsylo

Psylo has commands to enumerate all storage devices and to find all files that start with a particular string.

T1083
File and Directory Discovery
MalwareMobileOrder

MobileOrder has a command to upload to its C2 server information about files on the victim mobile device, including SD card size, installed app list, SMS content, contacts, and calling history.

T1095
Non-Application Layer Protocol
MalwareFakeM

Some variants of FakeM use SSL to communicate with C2 servers.

T1105
Ingress Tool Transfer
MalwareMobileOrder

MobileOrder has a command to download a file from the C2 server to the victim mobile device's SD card.

T1105
Ingress Tool Transfer
MalwareCallMe

CallMe has the capability to download a file to the victim from the C2 server.

T1105
Ingress Tool Transfer
MalwarePsylo

Psylo has a command to download a file to the system from its C2 server.

T1217
Browser Information Discovery
MalwareMobileOrder

MobileOrder has a command to upload to its C2 server victim browser bookmarks.

T1573.001
Symmetric Cryptography
MalwareFakeM

The original variant of FakeM encrypts C2 traffic using a custom encryption cipher that uses an XOR key of “YHCRA” and bit rotation between each XOR operation. Some variants of FakeM use RC4 to encrypt C2 traffic.

T1573.001
Symmetric Cryptography
MalwareCallMe

CallMe uses AES to encrypt C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.