ATT&CKReferencesMalwareBytes WoodyRAT Aug 2022

MalwareBytes WoodyRAT Aug 2022

MalwareBytes Threat Intelligence Team. (2022, August 3). Woody RAT: A new feature-rich malware spotted in the wild. Retrieved December 6, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples30

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareWoody RAT

Woody RAT can collect information from a compromised host.

T1012
Query Registry
MalwareWoody RAT

Woody RAT can search registry keys to identify antivirus programs on an compromised host.

T1016
System Network Configuration Discovery
MalwareWoody RAT

Woody RAT can retrieve network interface and proxy information.

T1016.001
Internet Connection Discovery
MalwareWoody RAT

Woody RAT can make `Ping` GET HTTP requests to its C2 server at regular intervals for network connectivity checks.

T1027.013
Encrypted/Encoded File
MalwareWoody RAT

Woody RAT has used Base64 encoded strings and scripts.

T1033
System Owner/User Discovery
MalwareWoody RAT

Woody RAT can retrieve a list of user accounts and usernames from an infected machine.

T1041
Exfiltration Over C2 Channel
MalwareWoody RAT

Woody RAT can exfiltrate files from an infected machine to its C2 server.

T1055
Process Injection
MalwareWoody RAT

Woody RAT can inject code into a targeted process by writing to the remote memory of an infected system and then create a remote thread.

T1055.012
Process Hollowing
MalwareWoody RAT

Woody RAT can create a suspended notepad process and write shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`.

T1057
Process Discovery
MalwareWoody RAT

Woody RAT can call `NtQuerySystemProcessInformation` with `SystemProcessInformation` to enumerate all running processes, including associated information such as PID, parent PID, image name, and owner.

T1059.001
PowerShell
MalwareWoody RAT

Woody RAT can execute PowerShell commands and scripts with the use of .NET DLL, `WoodyPowerSession`.

T1059.003
Windows Command Shell
MalwareWoody RAT

Woody RAT can execute commands using `cmd.exe`.

T1070.004
File Deletion
MalwareWoody RAT

Woody RAT has the ability to delete itself from disk by creating a suspended notepad process and writing shellcode to delete a file into the suspended process using `NtWriteVirtualMemory`.

T1071.001
Web Protocols
MalwareWoody RAT

Woody RAT can communicate with its C2 server using HTTP requests.

T1082
System Information Discovery
MalwareWoody RAT

Woody RAT can retrieve the following information from an infected machine: OS, architecture, computer name, OS build version, and environment variables.

T1083
File and Directory Discovery
MalwareWoody RAT

Woody RAT can list all files and their associated attributes, including filename, type, owner, creation time, last access time, last write time, size, and permissions.

T1087
Account Discovery
MalwareWoody RAT

Woody RAT can identify administrator accounts on an infected machine.

T1105
Ingress Tool Transfer
MalwareWoody RAT

Woody RAT can download files from its C2 server, including the .NET DLLs, `WoodySharpExecutor` and `WoodyPowerSession`.

T1106
Native API
MalwareWoody RAT

Woody RAT can use multiple native APIs, including `WriteProcessMemory`, `CreateProcess`, and `CreateRemoteThread` for process injection.

T1113
Screen Capture
MalwareWoody RAT

Woody RAT has the ability to take a screenshot of the infected host desktop using Windows GDI+.

T1140
Deobfuscate/Decode Files or Information
MalwareWoody RAT

Woody RAT can deobfuscate Base64-encoded strings and scripts.

T1203
Exploitation for Client Execution
MalwareWoody RAT

Woody RAT has relied on CVE-2022-30190 (Follina) for execution during delivery.

T1204.002
Malicious File
MalwareWoody RAT

Woody RAT has relied on users opening a malicious email attachment for execution.

T1518
Software Discovery
MalwareWoody RAT

Woody RAT can collect .NET, PowerShell, and Python information from an infected host.

T1518.001
Security Software Discovery
MalwareWoody RAT

Woody RAT can detect Avast Software, Doctor Web, Kaspersky, AVG, ESET, and Sophos antivirus programs.

T1566.001
Spearphishing Attachment
MalwareWoody RAT

Woody RAT has been delivered via malicious Word documents and archive files.

T1573.001
Symmetric Cryptography
MalwareWoody RAT

Woody RAT can use AES-CBC to encrypt data sent to its C2 server.

T1573.002
Asymmetric Cryptography
MalwareWoody RAT

Woody RAT can use RSA-4096 to encrypt data sent to its C2 server.

T1680
Local Storage Discovery
MalwareWoody RAT

Woody RAT can retrieve information about storage drives from an infected machine.

T1685
Disable or Modify Tools
MalwareWoody RAT

Woody RAT has suppressed all error reporting by calling `SetErrorMode` with 0x8007 as a parameter.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.