ATT&CKReferencesUnit 42 CARROTBAT January 2020

Unit 42 CARROTBAT January 2020

McCabe, A. (2020, January 23). The Fractured Statue Campaign: U.S. Government Agency Targeted in Spear-Phishing Attacks. Retrieved June 2, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
ToolCARROTBALL

CARROTBALL has used a custom base64 alphabet to decode files.

T1057
Process Discovery
MalwareSYSCON

SYSCON has the ability to use Tasklist to list running processes.

T1059.003
Windows Command Shell
MalwareSYSCON

SYSCON has the ability to execute commands through cmd on a compromised host.

T1059.003
Windows Command Shell
MalwareCARROTBAT

CARROTBAT has the ability to execute command line arguments on a compromised host.

T1071.002
File Transfer Protocols
MalwareSYSCON

SYSCON has the ability to use FTP in C2 communications.

T1071.002
File Transfer Protocols
ToolCARROTBALL

CARROTBALL has the ability to use FTP in C2 communications.

T1082
System Information Discovery
MalwareSYSCON

SYSCON has the ability to use Systeminfo to identify system information.

T1082
System Information Discovery
MalwareCARROTBAT

CARROTBAT has the ability to determine the operating system of the compromised host and whether Windows is being run with x86 or x64 architecture.

T1105
Ingress Tool Transfer
ToolCARROTBALL

CARROTBALL has the ability to download and install a remote payload.

T1204.002
Malicious File
ToolCARROTBALL

CARROTBALL has been executed through users being lured into opening malicious e-mail attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.