ATT&CKReferencesCybereason Molerats Dec 2020

Cybereason Molerats Dec 2020

Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareSharpStage

SharpStage can use WMI for execution.

T1047
Windows Management Instrumentation
MalwareMoleNet

MoleNet can perform WMI commands on the system.

T1053.005
Scheduled Task
MalwareSharpStage

SharpStage has a persistence component to write a scheduled task for the payload.

T1059.001
PowerShell
MalwareMoleNet

MoleNet can use PowerShell to set persistence.

T1059.001
PowerShell
MalwareSharpStage

SharpStage can execute arbitrary commands with PowerShell.

T1059.003
Windows Command Shell
MalwareSharpStage

SharpStage can execute arbitrary commands with the command line.

T1059.003
Windows Command Shell
MalwareMoleNet

MoleNet can execute commands via the command line utility.

T1059.003
Windows Command Shell
MalwareDropBook

DropBook can execute arbitrary shell commands on the victims' machines.

T1059.006
Python
MalwareDropBook

DropBook is a Python-based backdoor compiled with PyInstaller.

T1082
System Information Discovery
MalwareDropBook

DropBook has checked for the presence of Arabic language in the infected machine's settings.

T1082
System Information Discovery
MalwareMoleNet

MoleNet can collect information about the about the system.

T1083
File and Directory Discovery
MalwareDropBook

DropBook can collect the names of all files and folders in the Program Files directories.

T1102
Web Service
MalwareDropBook

DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions.

T1102
Web Service
MalwareSharpStage

SharpStage has used a legitimate web service for evading detection.

T1105
Ingress Tool Transfer
MalwareDropBook

DropBook can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareSharpStage

SharpStage has the ability to download and execute additional payloads via a DropBox API.

T1105
Ingress Tool Transfer
MalwareMoleNet

MoleNet can download additional payloads from the C2.

T1113
Screen Capture
MalwareSharpStage

SharpStage has the ability to capture the victim's screen.

T1140
Deobfuscate/Decode Files or Information
MalwareDropBook

DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules.

T1204.002
Malicious File
GroupMolerats

Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives.

T1518.001
Security Software Discovery
MalwareMoleNet

MoleNet can use WMI commands to check the system for firewall and antivirus software.

T1547.001
Registry Run Keys / Startup Folder
MalwareSharpStage

SharpStage has the ability to create persistence for the malware using the Registry autorun key and startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareMoleNet

MoleNet can achieve persitence on the infected machine by setting the Registry run key.

T1566.001
Spearphishing Attachment
GroupMolerats

Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.