ATT&CKReferencesKaspersky WIRTE November 2021

Kaspersky WIRTE November 2021

Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples25

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareLitePower

LitePower can query the Registry for keys added to execute COM hijacking.

T1033
System Owner/User Discovery
MalwareLitePower

LitePower can determine if the current user has admin privileges.

T1036.005
Match Legitimate Resource Name or Location
GroupWIRTE

WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate.

T1041
Exfiltration Over C2 Channel
MalwareLitePower

LitePower can send collected data, including screenshots, over its C2 channel.

T1053.005
Scheduled Task
MalwareLitePower

LitePower can create a scheduled task to enable persistence mechanisms.

T1059.001
PowerShell
MalwareLitePower

LitePower can use a PowerShell script to execute commands.

T1059.001
PowerShell
MalwareFerocious

Ferocious can use PowerShell scripts for execution.

T1059.005
Visual Basic
MalwareFerocious

Ferocious has the ability to use Visual Basic scripts for execution.

T1070.004
File Deletion
MalwareFerocious

Ferocious can delete files from a compromised host.

T1071.001
Web Protocols
MalwareLitePower

LitePower can use HTTP and HTTPS for C2 communications.

T1082
System Information Discovery
MalwareFerocious

Ferocious can use GET.WORKSPACE in Microsoft Excel to determine the OS version of the compromised host.

T1082
System Information Discovery
MalwareLitePower

LitePower has the ability to enumerate the OS architecture.

T1105
Ingress Tool Transfer
MalwareLitePower

LitePower has the ability to download payloads containing system commands to a compromised host.

T1106
Native API
MalwareLitePower

LitePower can use various API calls.

T1112
Modify Registry
MalwareFerocious

Ferocious has the ability to add a Class ID in the current user Registry hive to enable persistence mechanisms.

T1113
Screen Capture
MalwareLitePower

LitePower can take system screenshots and save them to `%AppData%`.

T1120
Peripheral Device Discovery
MalwareFerocious

Ferocious can run GET.WORKSPACE in Microsoft Excel to check if a mouse is present.

T1204.002
Malicious File
GroupWIRTE

WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads.

T1497.001
System Checks
MalwareFerocious

Ferocious can run anti-sandbox checks using the Microsoft Excel 4.0 function GET.WORKSPACE to determine the OS version, if there is a mouse present, and if the host is capable of playing sounds.

T1518.001
Security Software Discovery
MalwareLitePower

LitePower can identify installed AV software.

T1518.001
Security Software Discovery
MalwareFerocious

Ferocious has checked for AV software as part of its persistence process.

T1546.015
Component Object Model Hijacking
MalwareFerocious

Ferocious can use COM hijacking to establish persistence.

T1566.001
Spearphishing Attachment
GroupWIRTE

WIRTE has sent emails to intended victims with malicious MS Word and Excel attachments.

T1571
Non-Standard Port
GroupWIRTE

WIRTE has used HTTPS over ports 2083 and 2087 for C2.

T1680
Local Storage Discovery
MalwareLitePower

LitePower has the ability to list local drives.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.