ATT&CKReferencesUS-CERT TYPEFRAME June 2018

US-CERT TYPEFRAME June 2018

US-CERT. (2018, June 14). MAR-10135536-12 – North Korean Trojan: TYPEFRAME. Retrieved July 13, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1027.011
Fileless Storage
MalwareTYPEFRAME

TYPEFRAME can install and store encrypted configuration data under the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\laxhost.dll and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PrintConfigs.

T1027.013
Encrypted/Encoded File
MalwareTYPEFRAME

APIs and strings in some TYPEFRAME variants are RC4 encrypted. Another variant is encoded with XOR.

T1059.003
Windows Command Shell
MalwareTYPEFRAME

TYPEFRAME can uninstall malware components using a batch script. TYPEFRAME can execute commands using a shell.

T1059.005
Visual Basic
MalwareTYPEFRAME

TYPEFRAME has used a malicious Word document for delivery with VBA macros for execution.

T1070.004
File Deletion
MalwareTYPEFRAME

TYPEFRAME can delete files off the system.

T1083
File and Directory Discovery
MalwareTYPEFRAME

TYPEFRAME can search directories for files on the victim’s machine.

T1090
Proxy
MalwareTYPEFRAME

A TYPEFRAME variant can force the compromised system to function as a proxy server.

T1105
Ingress Tool Transfer
MalwareTYPEFRAME

TYPEFRAME can upload and download files to the victim’s machine.

T1112
Modify Registry
MalwareTYPEFRAME

TYPEFRAME can install encrypted configuration data under the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\laxhost.dll and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PrintConfigs.

T1140
Deobfuscate/Decode Files or Information
MalwareTYPEFRAME

One TYPEFRAME variant decrypts an archive using an RC4 key, then decompresses and installs the decrypted malicious DLL module. Another variant decodes the embedded file by XORing it with the value "0x35".

T1204.002
Malicious File
MalwareTYPEFRAME

A Word document delivering TYPEFRAME prompts the user to enable macro execution.

T1543.003
Windows Service
MalwareTYPEFRAME

TYPEFRAME variants can add malicious DLL modules as new services.TYPEFRAME can also delete services from the victim’s machine.

T1571
Non-Standard Port
MalwareTYPEFRAME

TYPEFRAME has used ports 443, 8080, and 8443 with a FakeTLS method.

T1680
Local Storage Discovery
MalwareTYPEFRAME

TYPEFRAME can gather the disk volume information.

T1686.003
Windows Host Firewall
MalwareTYPEFRAME

TYPEFRAME can open the Windows Firewall on the victim’s machine to allow incoming connections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.