ATT&CKReferencesSecurelist Brazilian Banking Malware July 2020

Securelist Brazilian Banking Malware July 2020

GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples43

TechniqueUsed byProcedure example
T1027.001
Binary Padding
MalwareJavali

Javali can use large obfuscated libraries to hinder detection and analysis.

T1027.002
Software Packing
MalwareMelcoz

Melcoz has been packed with VMProtect and Themida.

T1027.013
Encrypted/Encoded File
MalwareGrandoreiro

The Grandoreiro payload has been delivered encrypted with a custom XOR-based algorithm and also as a base64-encoded ZIP file.

T1027.013
Encrypted/Encoded File
MalwareAstaroth

Astaroth has used an XOR-based algorithm to encrypt payloads twice with different keys.

T1055.012
Process Hollowing
MalwareAstaroth

Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.

T1057
Process Discovery
MalwareJavali

Javali can monitor processes for open browsers and custom banking applications.

T1059.005
Visual Basic
MalwareMelcoz

Melcoz can use VBS scripts to execute malicious DLLs.

T1059.005
Visual Basic
MalwareJavali

Javali has used embedded VBScript to download malicious payloads from C2.

T1059.005
Visual Basic
MalwareAstaroth

Astaroth has used malicious VBS e-mail attachments for execution.

T1059.005
Visual Basic
MalwareGrandoreiro

Grandoreiro can use VBScript to execute malicious code.

T1059.007
JavaScript
MalwareAstaroth

Astaroth uses JavaScript to perform its core functionalities.

T1059.010
AutoHotKey & AutoIT
MalwareMelcoz

Melcoz has been distributed through an AutoIt loader script.

T1102.001
Dead Drop Resolver
MalwareAstaroth

Astaroth can store C2 information on cloud hosting services such as AWS and CloudFlare and websites like YouTube and Facebook.

T1102.001
Dead Drop Resolver
MalwareJavali

Javali can read C2 information from Google Documents and YouTube.

T1102.001
Dead Drop Resolver
MalwareGrandoreiro

Grandoreiro can obtain C2 information from Google Docs.

T1105
Ingress Tool Transfer
MalwareAstaroth

Astaroth uses certutil and BITSAdmin to download additional malware.

T1105
Ingress Tool Transfer
MalwareJavali

Javali can download payloads from remote C2 servers.

T1105
Ingress Tool Transfer
MalwareMelcoz

Melcoz has the ability to download additional files to a compromised host.

T1115
Clipboard Data
MalwareMelcoz

Melcoz can monitor content saved to the clipboard.

T1140
Deobfuscate/Decode Files or Information
MalwareAstaroth

Astaroth uses a fromCharCode() deobfuscation method to avoid explicitly writing execution commands and to hide its code.

T1185
Browser Session Hijacking
MalwareGrandoreiro

Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1185
Browser Session Hijacking
MalwareMelcoz

Melcoz can monitor the victim's browser for online banking sessions and display an overlay window to manipulate the session in the background.

T1189
Drive-by Compromise
MalwareGrandoreiro

Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer.

T1204.001
Malicious Link
MalwareMelcoz

Melcoz has gained execution through victims opening malicious links.

T1204.001
Malicious Link
MalwareJavali

Javali has achieved execution through victims clicking links to malicious websites.

T1204.002
Malicious File
MalwareAstaroth

Astaroth has used malicious files including VBS, LNK, and HTML for execution.

T1204.002
Malicious File
MalwareJavali

Javali has achieved execution through victims opening malicious attachments, including MSI files with embedded VBScript.

T1218.007
Msiexec
MalwareMelcoz

Melcoz can use MSI files with embedded VBScript for execution.

T1218.007
Msiexec
MalwareGrandoreiro

Grandoreiro can use MSI files to execute DLLs.

T1218.007
Msiexec
MalwareJavali

Javali has used the MSI installer to download and execute malicious payloads.

T1497.001
System Checks
MalwareAstaroth

Astaroth can check for Windows product ID's used by sandboxes and usernames and disk serial numbers associated with analyst environments.

T1555.003
Credentials from Web Browsers
MalwareJavali

Javali can capture login credentials from open browsers including Firefox, Chrome, Internet Explorer, and Edge.

T1555.003
Credentials from Web Browsers
MalwareMelcoz

Melcoz has the ability to steal credentials from web browsers.

T1564.004
NTFS File Attributes
MalwareAstaroth

Astaroth can abuse alternate data streams (ADS) to store content for malicious payloads.

T1565.002
Transmitted Data Manipulation
MalwareMelcoz

Melcoz can monitor the clipboard for cryptocurrency addresses and change the intended address to one controlled by the adversary.

T1566.001
Spearphishing Attachment
MalwareAstaroth

Astaroth has been delivered via malicious e-mail attachments.

T1566.001
Spearphishing Attachment
MalwareJavali

Javali has been delivered as malicious e-mail attachments.

T1566.002
Spearphishing Link
MalwareJavali

Javali has been delivered via malicious links embedded in e-mails.

T1566.002
Spearphishing Link
MalwareMelcoz

Melcoz has been spread through malicious links embedded in e-mails.

T1568.002
Domain Generation Algorithms
MalwareGrandoreiro

Grandoreiro can use a DGA for hiding C2 addresses, including use of an algorithm with a user-specific key that changes daily.

T1574.001
DLL
MalwareAstaroth

Astaroth can launch itself via DLL Search Order Hijacking.

T1574.001
DLL
MalwareMelcoz

Melcoz can use DLL hijacking to bypass security controls.

T1574.001
DLL
MalwareJavali

Javali can use DLL side-loading to load malicious DLLs into legitimate executables.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.