Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupWindigo | Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors. |
| T1016 System Network Configuration Discovery |
MalwareKessel | Kessel has collected the DNS address of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareBonadan | Bonadan can find the external IP address of the infected host. |
| T1027.013 Encrypted/Encoded File |
MalwareKessel | Kessel's configuration is hardcoded and RC4 encrypted within the binary. |
| T1030 Data Transfer Size Limits |
MalwareKessel | Kessel can split the data to be exilftrated into chunks that will fit in subdomains of DNS queries. |
| T1033 System Owner/User Discovery |
MalwareBonadan | Bonadan has discovered the username of the user running the backdoor. |
| T1041 Exfiltration Over C2 Channel |
MalwareKessel | Kessel has exfiltrated information gathered from the infected system to the C2 server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareKessel | Kessel can exfiltrate credentials and other information via HTTP POST request, TCP, and DNS. |
| T1057 Process Discovery |
MalwareBonadan | Bonadan can use the |
| T1059 Command and Scripting Interpreter |
GroupWindigo | Windigo has used a Perl script for information gathering. |
| T1059 Command and Scripting Interpreter |
MalwareBonadan | Bonadan can create bind and reverse shells on the infected system. |
| T1059 Command and Scripting Interpreter |
MalwareKessel | Kessel can create a reverse shell between the infected host and a specified system. |
| T1082 System Information Discovery |
MalwareKessel | Kessel has collected the system architecture, OS version, and MAC address information. |
| T1082 System Information Discovery |
MalwareBonadan | Bonadan has discovered the OS version, CPU model, and RAM size of the system it has been installed on. |
| T1082 System Information Discovery |
GroupWindigo | Windigo has used a script to detect which Linux distribution and version is currently installed on the system. |
| T1083 File and Directory Discovery |
GroupWindigo | Windigo has used a script to check for the presence of files created by OpenSSH backdoors. |
| T1090 Proxy |
MalwareKessel | Kessel can use a proxy during exfiltration if set in the configuration. |
| T1105 Ingress Tool Transfer |
MalwareBonadan | Bonadan can download additional modules from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareKessel | Kessel can download additional modules from the C2 server. |
| T1132.001 Standard Encoding |
MalwareKessel | Kessel has exfiltrated data via hexadecimal-encoded subdomain fields of DNS queries. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKessel | Kessel has decrypted the binary's configuration once the |
| T1496.001 Compute Hijacking |
MalwareBonadan | Bonadan can download an additional module which has a cryptocurrency mining extension. |
| T1518 Software Discovery |
GroupWindigo | Windigo has used a script to detect installed software on targeted systems. |
| T1554 Compromise Host Software Binary |
MalwareKessel | Kessel has maliciously altered the OpenSSH binary on targeted systems to create a backdoor. |
| T1554 Compromise Host Software Binary |
MalwareBonadan | Bonadan has maliciously altered the OpenSSH binary on targeted systems to create a backdoor. |
| T1556 Modify Authentication Process |
MalwareKessel | Kessel has trojanized the <sode>ssh_login</code> and |
| T1560 Archive Collected Data |
MalwareKessel | Kessel can RC4-encrypt credentials before sending to the C2. |
| T1573.001 Symmetric Cryptography |
MalwareBonadan | Bonadan can XOR-encrypt C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.