ATT&CKReferencesUS-CERT Volgmer Nov 2017

US-CERT Volgmer Nov 2017

US-CERT. (2017, November 22). Alert (TA17-318B): HIDDEN COBRA – North Korean Trojan: Volgmer. Retrieved December 7, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareVolgmer

Volgmer queries the system to identify existing services.

T1027.011
Fileless Storage
MalwareVolgmer

Volgmer stores an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1059.003
Windows Command Shell
MalwareVolgmer

Volgmer can execute commands on the victim's machine.

T1082
System Information Discovery
MalwareVolgmer

Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine.

T1083
File and Directory Discovery
MalwareVolgmer

Volgmer can list directories on a victim.

T1105
Ingress Tool Transfer
MalwareVolgmer

Volgmer can download remote files and additional payloads to the victim's machine.

T1543.003
Windows Service
MalwareVolgmer

Volgmer installs a copy of itself in a randomly selected service, then overwrites the ServiceDLL entry in the service's Registry entry. Some Volgmer variants also install .dll files as services with names generated by a list of hard-coded strings.

T1573.002
Asymmetric Cryptography
MalwareVolgmer

Some Volgmer variants use SSL to encrypt C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.