ATT&CKReferencesUnit 42 CARROTBAT November 2018

Unit 42 CARROTBAT November 2018

Grunzweig, J. and Wilhoit, K. (2018, November 29). The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia. Retrieved June 2, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareCARROTBAT

CARROTBAT has the ability to execute obfuscated commands on the infected host.

T1027.013
Encrypted/Encoded File
MalwareCARROTBAT

CARROTBAT has the ability to download a base64 encoded payload.

T1070.004
File Deletion
MalwareCARROTBAT

CARROTBAT has the ability to delete downloaded files from a compromised host.

T1071.002
File Transfer Protocols
MalwareSYSCON

SYSCON has the ability to use FTP in C2 communications.

T1082
System Information Discovery
MalwareCARROTBAT

CARROTBAT has the ability to determine the operating system of the compromised host and whether Windows is being run with x86 or x64 architecture.

T1105
Ingress Tool Transfer
MalwareCARROTBAT

CARROTBAT has the ability to download and execute a remote file via certutil.

T1204.002
Malicious File
MalwareSYSCON

SYSCON has been executed by luring victims to open malicious e-mail attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.