T1027 Obfuscated Files or Information |
MalwareBOOKWORM |
BOOKWORM has been delivered using self-extracting RAR archives. |
T1027 Obfuscated Files or Information |
GroupMustang Panda |
Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. |
T1033 System Owner/User Discovery |
MalwareBOOKWORM |
BOOKWORM has obtained the username from an infected host. |
T1036.004 Masquerade Task or Service |
MalwareBOOKWORM |
BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`. |
T1056.001 Keylogging |
MalwareBOOKWORM |
BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder. |
T1071.001 Web Protocols |
GroupMustang Panda |
Mustang Panda has communicated with its C2 via HTTP POST requests. |
T1071.001 Web Protocols |
MalwareBOOKWORM |
BOOKWORM has communicated with its C2 via HTTP POST requests. |
T1112 Modify Registry |
MalwareBOOKWORM |
BOOKWORM has modified Registry key values as part of its created service `DeviceSync`. |
T1115 Clipboard Data |
MalwareBOOKWORM |
BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard. |
T1140 Deobfuscate/Decode Files or Information |
MalwareBOOKWORM |
BOOKWORM has decoded its Base64 encoded payload prior to execution. BOOKWORM has also encrypted files with RC4 and has decrypted its payload prior to execution. |
T1140 Deobfuscate/Decode Files or Information |
GroupMustang Panda |
Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads. |
T1204.002 Malicious File |
GroupMustang Panda |
Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. |
T1543.003 Windows Service |
MalwareBOOKWORM |
BOOKWORM has created a service named `Microsoft Windows DeviceSync Service` at `HKLM\SYSTEM\CurrentControlSet\Services\DeviceSync\` to trigger execution when the system starts and to maintain persistence. |
T1553.002 Code Signing |
MalwareBOOKWORM |
BOOKWORM has used valid legitimate digital signatures and certificates to evade detection. |
T1553.002 Code Signing |
GroupMustang Panda |
Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
T1564.003 Hidden Window |
MalwareBOOKWORM |
BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module. |
T1573.001 Symmetric Cryptography |
GroupMustang Panda |
Mustang Panda has encrypted C2 communications with RC4. Mustang Panda has also leveraged encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO. |
T1573.001 Symmetric Cryptography |
MalwareBOOKWORM |
BOOKWORM has used encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO. |
T1574.001 DLL |
GroupMustang Panda |
Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. |
T1574.001 DLL |
MalwareBOOKWORM |
BOOKWORM has used DLL side-loading to execute the malicious payload. BOOKWORM has also side-loaded DLL components into a legitimate process, including Microsoft Malware Protection `MsMpEng.exe` and Kaspersky Anti-Virus `ushata.exe`. |
T1583.001 Domains |
GroupMustang Panda |
Mustang Panda has acquired C2 domains prior to operations. |