ATT&CKReferencesUnit 42 NETWIRE April 2020

Unit 42 NETWIRE April 2020

Duncan, B. (2020, April 3). GuLoader: Malspam Campaign Installing NetWire RAT. Retrieved January 7, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwareGuLoader

GuLoader can delete its executable from the AppData\Local\Temp directory on the compromised host.

T1071.001
Web Protocols
MalwareGuLoader

GuLoader can use HTTP to retrieve additional binaries.

T1095
Non-Application Layer Protocol
MalwareNETWIRE

NETWIRE can use TCP in C2 communications.

T1204.001
Malicious Link
MalwareGuLoader

GuLoader has relied upon users clicking on links to malicious documents.

T1204.001
Malicious Link
MalwareNETWIRE

NETWIRE has been executed through convincing victims into clicking malicious links.

T1204.002
Malicious File
MalwareGuLoader

The GuLoader executable has been retrieved via embedded macros in malicious Word documents.

T1204.002
Malicious File
MalwareNETWIRE

NETWIRE has been executed through luring victims into opening malicious documents.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETWIRE

NETWIRE creates a Registry start-up entry to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGuLoader

GuLoader can establish persistence via the Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce.

T1566.001
Spearphishing Attachment
MalwareNETWIRE

NETWIRE has been spread via e-mail campaigns utilizing malicious attachments.

T1566.002
Spearphishing Link
MalwareGuLoader

GuLoader has been spread in phishing campaigns using malicious web links.

T1566.002
Spearphishing Link
MalwareNETWIRE

NETWIRE has been spread via e-mail campaigns utilizing malicious links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.