ATT&CKReferencesTalos Oblique RAT March 2021

Talos Oblique RAT March 2021

Malhotra, A. (2021, March 2). ObliqueRAT returns with new campaign using hijacked websites. Retrieved September 2, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1025
Data from Removable Media
MalwareObliqueRAT

ObliqueRAT has the ability to extract data from removable devices connected to the endpoint.

T1027.003
Steganography
MalwareObliqueRAT

ObliqueRAT can hide its payload in BMP images hosted on compromised websites.

T1030
Data Transfer Size Limits
MalwareObliqueRAT

ObliqueRAT can break large files of interest into smaller chunks to prepare them for exfiltration.

T1033
System Owner/User Discovery
MalwareObliqueRAT

ObliqueRAT can check for blocklisted usernames on infected endpoints.

T1057
Process Discovery
MalwareObliqueRAT

ObliqueRAT can check for blocklisted process names on a compromised host.

T1074.001
Local Data Staging
MalwareObliqueRAT

ObliqueRAT can copy specific files, webcam captures, and screenshots to local directories.

T1082
System Information Discovery
MalwareObliqueRAT

ObliqueRAT has the ability to check for blocklisted computer names on infected endpoints.

T1083
File and Directory Discovery
MalwareObliqueRAT

ObliqueRAT has the ability to recursively enumerate files on an infected endpoint.

T1113
Screen Capture
MalwareObliqueRAT

ObliqueRAT can capture a screenshot of the current screen.

T1120
Peripheral Device Discovery
MalwareObliqueRAT

ObliqueRAT can discover pluggable/removable drives to extract files from.

T1125
Video Capture
MalwareObliqueRAT

ObliqueRAT can capture images from webcams on compromised hosts.

T1204.001
Malicious Link
GroupTransparent Tribe

Transparent Tribe has directed users to open URLs hosting malicious content.

T1204.001
Malicious Link
MalwareObliqueRAT

ObliqueRAT has gained execution on targeted systems through luring users to click on links to malicious URLs.

T1204.002
Malicious File
GroupTransparent Tribe

Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems.

T1497.001
System Checks
MalwareObliqueRAT

ObliqueRAT can halt execution if it identifies processes belonging to virtual machine software or analysis tools.

T1547.001
Registry Run Keys / Startup Folder
MalwareObliqueRAT

ObliqueRAT can gain persistence by a creating a shortcut in the infected user's Startup directory.

T1566.001
Spearphishing Attachment
GroupTransparent Tribe

Transparent Tribe has sent spearphishing e-mails with attachments to deliver malicious payloads.

T1566.002
Spearphishing Link
GroupTransparent Tribe

Transparent Tribe has embedded links to malicious downloads in e-mails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.