ATT&CKReferencesPWC KeyBoys Feb 2017

PWC KeyBoys Feb 2017

Parys, B. (2017, February 11). The KeyBoys are back in town. Retrieved June 13, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareKeyBoy

KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic.

T1016
System Network Configuration Discovery
MalwareKeyBoy

KeyBoy can determine the public or WAN IP address for the system.

T1059.001
PowerShell
MalwareKeyBoy

KeyBoy uses PowerShell commands to download and execute payloads.

T1059.003
Windows Command Shell
MalwareKeyBoy

KeyBoy can launch interactive shells for communicating with the victim machine.

T1070.006
Timestomp
MalwareKeyBoy

KeyBoy time-stomped its DLL in order to evade detection.

T1082
System Information Discovery
MalwareKeyBoy

KeyBoy can gather extended system information, such as information about the operating system and memory.

T1083
File and Directory Discovery
MalwareKeyBoy

KeyBoy has a command to launch a file browser or explorer on the system.

T1105
Ingress Tool Transfer
MalwareKeyBoy

KeyBoy has a download and upload functionality.

T1113
Screen Capture
MalwareKeyBoy

KeyBoy has a command to perform screen grabbing.

T1543.003
Windows Service
GroupTropic Trooper

Tropic Trooper has installed a service pointing to a malicious DLL dropped to disk.

T1547.004
Winlogon Helper DLL
MalwareKeyBoy

KeyBoy issues the command reg add “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon” to achieve persistence.

T1559.002
Dynamic Data Exchange
MalwareKeyBoy

KeyBoy uses the Dynamic Data Exchange (DDE) protocol to download remote payloads.

T1564.003
Hidden Window
MalwareKeyBoy

KeyBoy uses -w Hidden to conceal a PowerShell window that downloads a payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.