Zykov, K. (2020, August 13). CactusPete APT group’s updated Bisonal backdoor. Retrieved May 5, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareBisonal | Bisonal can execute |
| T1057 Process Discovery |
MalwareBisonal | Bisonal can obtain a list of running processes on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareBisonal | Bisonal has launched cmd.exe and used the ShellExecuteW() API function to execute commands on the system. |
| T1070.004 File Deletion |
MalwareBisonal | Bisonal will delete its dropper and VBS scripts from the victim’s machine. |
| T1071.001 Web Protocols |
MalwareBisonal | Bisonal has used HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwareBisonal | Bisonal has used commands and API calls to gather system information. |
| T1083 File and Directory Discovery |
MalwareBisonal | Bisonal can retrieve a file listing from the system. |
| T1105 Ingress Tool Transfer |
MalwareBisonal | Bisonal has the capability to download files to execute on the victim’s machine. |
| T1124 System Time Discovery |
MalwareBisonal | Bisonal can check the system time set on the infected host. |
| T1132.001 Standard Encoding |
MalwareBisonal | Bisonal has encoded binary data with Base64 and ASCII. |
| T1203 Exploitation for Client Execution |
GroupTonto Team | Tonto Team has exploited Microsoft vulnerabilities, including CVE-2018-0798, CVE-2018-8174, CVE-2018-0802, CVE-2017-11882, CVE-2019-9489 CVE-2020-8468, and CVE-2018-0798 to enable execution of their delivered malicious payloads. |
| T1497.003 Time Based Checks |
MalwareBisonal | Bisonal has checked if the malware is running in a virtual environment with the anti-debug function GetTickCount() to compare the timing. |
| T1573.001 Symmetric Cryptography |
MalwareBisonal | Bisonal variants reported on in 2014 and 2015 used a simple XOR cipher for C2. Some Bisonal samples encrypt C2 communications with RC4. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.