ATT&CKReferencesUnit42 Bookworm Nov2015

Unit42 Bookworm Nov2015

Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareBOOKWORM

BOOKWORM has been delivered using self-extracting RAR archives.

T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1033
System Owner/User Discovery
MalwareBOOKWORM

BOOKWORM has obtained the username from an infected host.

T1036.004
Masquerade Task or Service
MalwareBOOKWORM

BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`.

T1056.001
Keylogging
MalwareBOOKWORM

BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder.

T1071.001
Web Protocols
GroupMustang Panda

Mustang Panda has communicated with its C2 via HTTP POST requests.

T1071.001
Web Protocols
MalwareBOOKWORM

BOOKWORM has communicated with its C2 via HTTP POST requests.

T1112
Modify Registry
MalwareBOOKWORM

BOOKWORM has modified Registry key values as part of its created service `DeviceSync`.

T1115
Clipboard Data
MalwareBOOKWORM

BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard.

T1140
Deobfuscate/Decode Files or Information
MalwareBOOKWORM

BOOKWORM has decoded its Base64 encoded payload prior to execution. BOOKWORM has also encrypted files with RC4 and has decrypted its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
GroupMustang Panda

Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1543.003
Windows Service
MalwareBOOKWORM

BOOKWORM has created a service named `Microsoft Windows DeviceSync Service` at `HKLM\SYSTEM\CurrentControlSet\Services\DeviceSync\` to trigger execution when the system starts and to maintain persistence.

T1553.002
Code Signing
MalwareBOOKWORM

BOOKWORM has used valid legitimate digital signatures and certificates to evade detection.

T1553.002
Code Signing
GroupMustang Panda

Mustang Panda has used valid legitimate digital signatures and certificates to evade detection.

T1564.003
Hidden Window
MalwareBOOKWORM

BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module.

T1573.001
Symmetric Cryptography
GroupMustang Panda

Mustang Panda has encrypted C2 communications with RC4. Mustang Panda has also leveraged encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO.

T1573.001
Symmetric Cryptography
MalwareBOOKWORM

BOOKWORM has used encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwareBOOKWORM

BOOKWORM has used DLL side-loading to execute the malicious payload. BOOKWORM has also side-loaded DLL components into a legitimate process, including Microsoft Malware Protection `MsMpEng.exe` and Kaspersky Anti-Virus `ushata.exe`.

T1583.001
Domains
GroupMustang Panda

Mustang Panda has acquired C2 domains prior to operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.