ATT&CKReferencesESET InvisiMole June 2018

ESET InvisiMole June 2018

Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples41

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareInvisiMole

InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP.

T1005
Data from Local System
MalwareInvisiMole

InvisiMole can collect data from the system, and can monitor changes in specified directories.

T1007
System Service Discovery
MalwareInvisiMole

InvisiMole can obtain running services on the victim.

T1008
Fallback Channels
MalwareInvisiMole

InvisiMole has been configured with several servers available for alternate C2 communications.

T1010
Application Window Discovery
MalwareInvisiMole

InvisiMole can enumerate windows and child windows on a compromised host.

T1012
Query Registry
MalwareInvisiMole

InvisiMole can enumerate Registry values, keys, and data.

T1016
System Network Configuration Discovery
MalwareInvisiMole

InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID.

T1027
Obfuscated Files or Information
MalwareInvisiMole

InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format.

T1033
System Owner/User Discovery
MalwareInvisiMole

InvisiMole lists local users and session information.

T1036.005
Match Legitimate Resource Name or Location
MalwareInvisiMole

InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder.

T1057
Process Discovery
MalwareInvisiMole

InvisiMole can obtain a list of running processes.

T1059.003
Windows Command Shell
MalwareInvisiMole

InvisiMole can launch a remote shell to execute commands.

T1070.004
File Deletion
MalwareInvisiMole

InvisiMole has deleted files and directories including XML and files successfully uploaded to C2 servers.

T1070.005
Network Share Connection Removal
MalwareInvisiMole

InvisiMole can disconnect previously connected remote drives.

T1070.006
Timestomp
MalwareInvisiMole

InvisiMole samples were timestomped by the authors by setting the PE timestamps to all zero values. InvisiMole also has a built-in command to modify file times.

T1071.001
Web Protocols
MalwareInvisiMole

InvisiMole uses HTTP for C2 communications.

T1074.001
Local Data Staging
MalwareInvisiMole

InvisiMole determines a working directory where it stores all the gathered data about the compromised machine.

T1082
System Information Discovery
MalwareInvisiMole

InvisiMole can gather information on the OS version, computer name, DEP policy, and memory size.

T1083
File and Directory Discovery
MalwareInvisiMole

InvisiMole can list information about files in a directory and recently opened or used documents. InvisiMole can also search for specific files by supplied file mask.

T1087.001
Local Account
MalwareInvisiMole

InvisiMole has a command to list account information on the victim’s machine.

T1090.001
Internal Proxy
MalwareInvisiMole

InvisiMole can function as a proxy to create a server that relays communication between the client and C&C server, or between two clients.

T1090.002
External Proxy
MalwareInvisiMole

InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication.

T1105
Ingress Tool Transfer
MalwareInvisiMole

InvisiMole can upload files to the victim's machine for operations.

T1112
Modify Registry
MalwareInvisiMole

InvisiMole has a command to create, set, copy, or delete a specified Registry key or value.

T1113
Screen Capture
MalwareInvisiMole

InvisiMole can capture screenshots of not only the entire screen, but of each separate window open, in case they are overlapping.

T1119
Automated Collection
MalwareInvisiMole

InvisiMole can sort and collect specific documents as well as generate a list of all files on a newly inserted drive and store them in an encrypted file.

T1123
Audio Capture
MalwareInvisiMole

InvisiMole can record sound using input audio devices.

T1124
System Time Discovery
MalwareInvisiMole

InvisiMole gathers the local system time from the victim’s machine.

T1125
Video Capture
MalwareInvisiMole

InvisiMole can remotely activate the victim’s webcam to capture content.

T1135
Network Share Discovery
MalwareInvisiMole

InvisiMole can gather network share information.

T1140
Deobfuscate/Decode Files or Information
MalwareInvisiMole

InvisiMole can decrypt, unpack and load a DLL from its resources, or from blobs encrypted with Data Protection API, two-key triple DES, and variations of the XOR cipher.

T1490
Inhibit System Recovery
MalwareInvisiMole

InvisiMole can can remove all system restore points.

T1518
Software Discovery
MalwareInvisiMole

InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system.

T1548.002
Bypass User Account Control
MalwareInvisiMole

InvisiMole can use fileless UAC bypass and create an elevated COM object to escalate privileges.

T1560.001
Archive via Utility
MalwareInvisiMole

InvisiMole uses WinRAR to compress data that is intended to be exfiltrated.

T1560.002
Archive via Library
MalwareInvisiMole

InvisiMole can use zlib to compress and decompress data.

T1560.003
Archive via Custom Method
MalwareInvisiMole

InvisiMole uses a variation of the XOR cipher to encrypt files before exfiltration.

T1573.001
Symmetric Cryptography
MalwareInvisiMole

InvisiMole uses variations of a simple XOR encryption routine for C&C communications.

T1574.001
DLL
MalwareInvisiMole

InvisiMole can be launched by using DLL search order hijacking in which the wrapper DLL is placed in the same folder as explorer.exe and loaded during startup into the Windows Explorer process instead of the legitimate library.

T1680
Local Storage Discovery
MalwareInvisiMole

InvisiMole can gather information on the mapped drives and system volume serial number.

T1686
Disable or Modify System Firewall
MalwareInvisiMole

InvisiMole has a command to disable routing and the Firewall on the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.