ATT&CKReferencesUnit42 Molerat Mar 2020

Unit42 Molerat Mar 2020

Falcone, R., et al. (2020, March 3). Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations. Retrieved December 14, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareSpark

Spark has been packed with Enigma Protector to obfuscate its contents.

T1033
System Owner/User Discovery
MalwareSpark

Spark has run the whoami command and has a built-in command to identify the user logged in.

T1041
Exfiltration Over C2 Channel
MalwareSpark

Spark has exfiltrated data over the C2 channel.

T1053.005
Scheduled Task
GroupMolerats

Molerats has created scheduled tasks to persistently run VBScripts.

T1059.003
Windows Command Shell
MalwareSpark

Spark can use cmd.exe to run commands.

T1059.005
Visual Basic
GroupMolerats

Molerats used various implants, including those built with VBScript, on target machines.

T1071.001
Web Protocols
MalwareSpark

Spark has used HTTP POST requests to communicate with its C2 server to receive commands.

T1082
System Information Discovery
MalwareSpark

Spark can collect the hostname, keyboard layout, and language from the system.

T1105
Ingress Tool Transfer
GroupMolerats

Molerats used executables to download malicious files from different sources.

T1132.001
Standard Encoding
MalwareSpark

Spark has encoded communications with the C2 server with base64.

T1140
Deobfuscate/Decode Files or Information
MalwareSpark

Spark has used a custom XOR algorithm to decrypt the payload.

T1204.001
Malicious Link
GroupMolerats

Molerats has sent malicious links via email trick users into opening a RAR archive and running an executable.

T1204.002
Malicious File
GroupMolerats

Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives.

T1218.007
Msiexec
GroupMolerats

Molerats has used msiexec.exe to execute an MSI payload.

T1497.002
User Activity Based Checks
MalwareSpark

Spark has used a splash screen to check whether an user actively clicks on the screen before running malicious code.

T1566.001
Spearphishing Attachment
GroupMolerats

Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments.

T1614.001
System Language Discovery
MalwareSpark

Spark has checked the results of the GetKeyboardLayoutList and the language name returned by GetLocaleInfoA to make sure they contain the word “Arabic” before executing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.