Falcone, R., et al. (2020, March 3). Molerats Delivers Spark Backdoor to Government and Telecommunications Organizations. Retrieved December 14, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareSpark | Spark has been packed with Enigma Protector to obfuscate its contents. |
| T1033 System Owner/User Discovery |
MalwareSpark | Spark has run the whoami command and has a built-in command to identify the user logged in. |
| T1041 Exfiltration Over C2 Channel |
MalwareSpark | Spark has exfiltrated data over the C2 channel. |
| T1053.005 Scheduled Task |
GroupMolerats | Molerats has created scheduled tasks to persistently run VBScripts. |
| T1059.003 Windows Command Shell |
MalwareSpark | Spark can use cmd.exe to run commands. |
| T1059.005 Visual Basic |
GroupMolerats | Molerats used various implants, including those built with VBScript, on target machines. |
| T1071.001 Web Protocols |
MalwareSpark | Spark has used HTTP POST requests to communicate with its C2 server to receive commands. |
| T1082 System Information Discovery |
MalwareSpark | Spark can collect the hostname, keyboard layout, and language from the system. |
| T1105 Ingress Tool Transfer |
GroupMolerats | Molerats used executables to download malicious files from different sources. |
| T1132.001 Standard Encoding |
MalwareSpark | Spark has encoded communications with the C2 server with base64. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSpark | Spark has used a custom XOR algorithm to decrypt the payload. |
| T1204.001 Malicious Link |
GroupMolerats | Molerats has sent malicious links via email trick users into opening a RAR archive and running an executable. |
| T1204.002 Malicious File |
GroupMolerats | Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives. |
| T1218.007 Msiexec |
GroupMolerats | Molerats has used msiexec.exe to execute an MSI payload. |
| T1497.002 User Activity Based Checks |
MalwareSpark | Spark has used a splash screen to check whether an user actively clicks on the screen before running malicious code. |
| T1566.001 Spearphishing Attachment |
GroupMolerats | Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments. |
| T1614.001 System Language Discovery |
MalwareSpark | Spark has checked the results of the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.