ATT&CKReferencesCarbon Black HotCroissant April 2020

Carbon Black HotCroissant April 2020

Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareHotCroissant

HotCroissant has the ability to retrieve a list of services on the infected host.

T1010
Application Window Discovery
MalwareHotCroissant

HotCroissant has the ability to list the names of all open windows on the infected host.

T1016
System Network Configuration Discovery
MalwareRifdoor

Rifdoor has the ability to identify the IP address of the compromised host.

T1027.001
Binary Padding
MalwareRifdoor

Rifdoor has added four additional bytes of data upon launching, then saved the changed version as C:\ProgramData\Initech\Initech.exe.

T1027.002
Software Packing
MalwareHotCroissant

HotCroissant has used the open source UPX executable packer.

T1027.013
Encrypted/Encoded File
MalwareRifdoor

Rifdoor has encrypted strings with a single byte XOR algorithm.

T1027.013
Encrypted/Encoded File
MalwareHotCroissant

HotCroissant has encrypted strings with single-byte XOR and base64 encoded RC4.

T1033
System Owner/User Discovery
MalwareRifdoor

Rifdoor has the ability to identify the username on the compromised host.

T1033
System Owner/User Discovery
MalwareHotCroissant

HotCroissant has the ability to collect the username on the infected host.

T1041
Exfiltration Over C2 Channel
MalwareHotCroissant

HotCroissant has the ability to download files from the infected host to the command and control (C2) server.

T1053.005
Scheduled Task
MalwareHotCroissant

HotCroissant has attempted to install a scheduled task named “Java Maintenance64” on startup to establish persistence.

T1057
Process Discovery
MalwareHotCroissant

HotCroissant has the ability to list running processes on the infected host.

T1059.003
Windows Command Shell
MalwareHotCroissant

HotCroissant can remotely open applications on the infected host with the ShellExecuteA command.

T1070.004
File Deletion
MalwareHotCroissant

HotCroissant has the ability to clean up installed files, delete files, and delete itself from the victim’s machine.

T1082
System Information Discovery
MalwareRifdoor

Rifdoor has the ability to identify the Windows version on the compromised host.

T1083
File and Directory Discovery
MalwareHotCroissant

HotCroissant has the ability to retrieve a list of files in a given directory as well as drives and drive types.

T1105
Ingress Tool Transfer
MalwareHotCroissant

HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine.

T1113
Screen Capture
MalwareHotCroissant

HotCroissant has the ability to do real time screen viewing on an infected host.

T1204.002
Malicious File
MalwareRifdoor

Rifdoor has been executed from malicious Excel or Word documents containing macros.

T1489
Service Stop
MalwareHotCroissant

HotCroissant has the ability to stop services on the infected host.

T1518
Software Discovery
MalwareHotCroissant

HotCroissant can retrieve a list of applications from the SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareRifdoor

Rifdoor has created a new registry entry at HKEY_CURRENT_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Graphics with a value of C:\ProgramData\Initech\Initech.exe /run.

T1564.003
Hidden Window
MalwareHotCroissant

HotCroissant has the ability to hide the window for operations performed on a given file.

T1566.001
Spearphishing Attachment
MalwareRifdoor

Rifdoor has been distributed in e-mails with malicious Excel or Word documents.

T1573.001
Symmetric Cryptography
MalwareHotCroissant

HotCroissant has compressed network communications and encrypted them with a custom stream cipher.

T1573.001
Symmetric Cryptography
MalwareRifdoor

Rifdoor has encrypted command and control (C2) communications with a stream cipher.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.