ATT&CKReferencesUnit 42 Bisonal July 2018

Unit 42 Bisonal July 2018

Hayashi, K., Ray, V. (2018, July 31). Bisonal Malware Used in Attacks Against Russia and South Korea. Retrieved August 7, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareBisonal

Bisonal can execute ipconfig on the victim’s machine.

T1027.013
Encrypted/Encoded File
MalwareBisonal

Bisonal's DLL file and non-malicious decoy file are encrypted with RC4 and some function name strings are obfuscated.

T1057
Process Discovery
MalwareBisonal

Bisonal can obtain a list of running processes on the victim’s machine.

T1059.003
Windows Command Shell
MalwareBisonal

Bisonal has launched cmd.exe and used the ShellExecuteW() API function to execute commands on the system.

T1059.005
Visual Basic
MalwareBisonal

Bisonal's dropper creates VBS scripts on the victim’s machine.

T1070.004
File Deletion
MalwareBisonal

Bisonal will delete its dropper and VBS scripts from the victim’s machine.

T1071.001
Web Protocols
MalwareBisonal

Bisonal has used HTTP for C2 communications.

T1082
System Information Discovery
MalwareBisonal

Bisonal has used commands and API calls to gather system information.

T1105
Ingress Tool Transfer
MalwareBisonal

Bisonal has the capability to download files to execute on the victim’s machine.

T1140
Deobfuscate/Decode Files or Information
MalwareBisonal

Bisonal has decoded strings in the malware using XOR and RC4.

T1218.011
Rundll32
MalwareBisonal

Bisonal has used rundll32.exe to execute as part of the Registry Run key it adds: HKEY_CURRENT_USER \Software\Microsoft\Windows\CurrentVersion\Run\”vert” = “rundll32.exe c:\windows\temp\pvcu.dll , Qszdez”.

T1547.001
Registry Run Keys / Startup Folder
MalwareBisonal

Bisonal has added itself to the Registry key HKEY_CURRENT_USER\Software\Microsoft\CurrentVersion\Run\ for persistence.

T1573.001
Symmetric Cryptography
MalwareBisonal

Bisonal variants reported on in 2014 and 2015 used a simple XOR cipher for C2. Some Bisonal samples encrypt C2 communications with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.