ATT&CKReferencesUnit 42 WhisperGate January 2022

Unit 42 WhisperGate January 2022

Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareWhisperGate

WhisperGate can use PowerShell to support multiple actions including execution and defense evasion.

T1059.003
Windows Command Shell
MalwareWhisperGate

WhisperGate can use `cmd.exe` to execute commands.

T1059.005
Visual Basic
MalwareWhisperGate

WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender.

T1071.001
Web Protocols
MalwareWhisperGate

WhisperGate can make an HTTPS connection to download additional files.

T1083
File and Directory Discovery
MalwareWhisperGate

WhisperGate can locate files based on hardcoded file extensions.

T1102
Web Service
MalwareWhisperGate

WhisperGate can download additional payloads hosted on a Discord channel.

T1105
Ingress Tool Transfer
MalwareWhisperGate

WhisperGate can download additional stages of malware from a Discord CDN channel.

T1218.004
InstallUtil
MalwareWhisperGate

WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender.

T1485
Data Destruction
MalwareWhisperGate

WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions.

T1497.001
System Checks
MalwareWhisperGate

WhisperGate can stop its execution when it recognizes the presence of certain monitoring tools.

T1518.001
Security Software Discovery
MalwareWhisperGate

WhisperGate can recognize the presence of monitoring tools on a target system.

T1561.002
Disk Structure Wipe
MalwareWhisperGate

WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader.

T1569.002
Service Execution
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe via `sc.exe`.

T1685
Disable or Modify Tools
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.