ATT&CKReferencesTalos NavRAT May 2018

Talos NavRAT May 2018

Mercer, W., Rascagneres, P. (2018, May 31). NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea. Retrieved June 11, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1055
Process Injection
MalwareNavRAT

NavRAT copies itself into a running Internet Explorer process to evade detection.

T1056.001
Keylogging
MalwareNavRAT

NavRAT logs the keystrokes on the targeted system.

T1057
Process Discovery
MalwareNavRAT

NavRAT uses tasklist /v to check running processes.

T1059.003
Windows Command Shell
MalwareNavRAT

NavRAT leverages cmd.exe to perform discovery techniques. NavRAT loads malicious shellcode and executes it in memory.

T1071.003
Mail Protocols
MalwareNavRAT

NavRAT uses the email platform, Naver, for C2 communications, leveraging SMTP.

T1074.001
Local Data Staging
MalwareNavRAT

NavRAT writes multiple outputs to a TMP file using the >> method.

T1082
System Information Discovery
MalwareNavRAT

NavRAT uses systeminfo on a victim’s machine.

T1105
Ingress Tool Transfer
MalwareNavRAT

NavRAT can download files remotely.

T1547.001
Registry Run Keys / Startup Folder
MalwareNavRAT

NavRAT creates a Registry key to ensure a file gets executed upon reboot in order to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.