ATT&CKReferencesESET TeleBots Oct 2018

ESET TeleBots Oct 2018

Cherepanov, A., Lipovsky, R. (2018, October 11). New TeleBots backdoor: First evidence linking Industroyer to NotPetya. Retrieved November 27, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1027.011
Fileless Storage
MalwareExaramel for Windows

Exaramel for Windows stores the backdoor's configuration in the Registry in XML format.

T1027.013
Encrypted/Encoded File
MalwareExaramel for Linux

Exaramel for Linux uses RC4 for encrypting the configuration.

T1036.004
Masquerade Task or Service
MalwareExaramel for Windows

The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV” in an apparent attempt to masquerade as a legitimate service.

T1053.003
Cron
MalwareExaramel for Linux

Exaramel for Linux uses crontab for persistence if it does not have root privileges.

T1059.003
Windows Command Shell
MalwareExaramel for Windows

Exaramel for Windows has a command to launch a remote shell and executes commands on the victim’s machine.

T1059.004
Unix Shell
MalwareExaramel for Linux

Exaramel for Linux has a command to execute a shell command on the system.

T1059.005
Visual Basic
MalwareExaramel for Windows

Exaramel for Windows has a command to execute VBS scripts on the victim’s machine.

T1071.001
Web Protocols
MalwareExaramel for Linux

Exaramel for Linux uses HTTPS for C2 communications.

T1074.001
Local Data Staging
MalwareExaramel for Windows

Exaramel for Windows specifies a path to store files scheduled for exfiltration.

T1105
Ingress Tool Transfer
MalwareExaramel for Linux

Exaramel for Linux has a command to download a file from and to a remote C2 server.

T1112
Modify Registry
MalwareExaramel for Windows

Exaramel for Windows adds the configuration to the Registry in XML format.

T1543.002
Systemd Service
MalwareExaramel for Linux

Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root.

T1543.003
Windows Service
MalwareExaramel for Windows

The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV.”

T1560
Archive Collected Data
MalwareExaramel for Windows

Exaramel for Windows automatically encrypts files before sending them to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.