ATT&CKReferencesUS-CERT KEYMARBLE Aug 2018

US-CERT KEYMARBLE Aug 2018

US-CERT. (2018, August 09). MAR-10135536-17 – North Korean Trojan: KEYMARBLE. Retrieved August 16, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareKEYMARBLE

KEYMARBLE gathers the MAC address of the victim’s machine.

T1057
Process Discovery
MalwareKEYMARBLE

KEYMARBLE can obtain a list of running processes on the system.

T1059.003
Windows Command Shell
MalwareKEYMARBLE

KEYMARBLE can execute shell commands using cmd.exe.

T1070.004
File Deletion
MalwareKEYMARBLE

KEYMARBLE has the capability to delete files off the victim’s machine.

T1082
System Information Discovery
MalwareKEYMARBLE

KEYMARBLE has the capability to collect the computer name, language settings, the OS version, CPU information, and time elapsed since system start.

T1083
File and Directory Discovery
MalwareKEYMARBLE

KEYMARBLE has a command to search for files on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareKEYMARBLE

KEYMARBLE can upload files to the victim’s machine and can download additional payloads.

T1112
Modify Registry
MalwareKEYMARBLE

KEYMARBLE has a command to create Registry entries for storing data under HKEY_CURRENT_USER\SOFTWARE\Microsoft\WABE\DataPath.

T1113
Screen Capture
MalwareKEYMARBLE

KEYMARBLE can capture screenshots of the victim’s machine.

T1573.001
Symmetric Cryptography
MalwareKEYMARBLE

KEYMARBLE uses a customized XOR algorithm to encrypt C2 communications.

T1680
Local Storage Discovery
MalwareKEYMARBLE

KEYMARBLE has the capability to collect information on disk devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.