Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareSharpStage | SharpStage can use WMI for execution. |
| T1047 Windows Management Instrumentation |
MalwareMoleNet | MoleNet can perform WMI commands on the system. |
| T1053.005 Scheduled Task |
MalwareSharpStage | SharpStage has a persistence component to write a scheduled task for the payload. |
| T1059.001 PowerShell |
MalwareMoleNet | MoleNet can use PowerShell to set persistence. |
| T1059.001 PowerShell |
MalwareSharpStage | SharpStage can execute arbitrary commands with PowerShell. |
| T1059.003 Windows Command Shell |
MalwareSharpStage | SharpStage can execute arbitrary commands with the command line. |
| T1059.003 Windows Command Shell |
MalwareMoleNet | MoleNet can execute commands via the command line utility. |
| T1059.003 Windows Command Shell |
MalwareDropBook | DropBook can execute arbitrary shell commands on the victims' machines. |
| T1059.006 Python |
MalwareDropBook | DropBook is a Python-based backdoor compiled with PyInstaller. |
| T1082 System Information Discovery |
MalwareDropBook | DropBook has checked for the presence of Arabic language in the infected machine's settings. |
| T1082 System Information Discovery |
MalwareMoleNet | MoleNet can collect information about the about the system. |
| T1083 File and Directory Discovery |
MalwareDropBook | DropBook can collect the names of all files and folders in the Program Files directories. |
| T1102 Web Service |
MalwareDropBook | DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions. |
| T1102 Web Service |
MalwareSharpStage | SharpStage has used a legitimate web service for evading detection. |
| T1105 Ingress Tool Transfer |
MalwareDropBook | DropBook can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareSharpStage | SharpStage has the ability to download and execute additional payloads via a DropBox API. |
| T1105 Ingress Tool Transfer |
MalwareMoleNet | MoleNet can download additional payloads from the C2. |
| T1113 Screen Capture |
MalwareSharpStage | SharpStage has the ability to capture the victim's screen. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDropBook | DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules. |
| T1204.002 Malicious File |
GroupMolerats | Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives. |
| T1518.001 Security Software Discovery |
MalwareMoleNet | MoleNet can use WMI commands to check the system for firewall and antivirus software. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSharpStage | SharpStage has the ability to create persistence for the malware using the Registry autorun key and startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMoleNet | MoleNet can achieve persitence on the infected machine by setting the Registry run key. |
| T1566.001 Spearphishing Attachment |
GroupMolerats | Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.