ATT&CKReferencesUnit42 BendyBear Feb 2021

Unit42 BendyBear Feb 2021

Harbison, M. (2021, February 9). BendyBear: Novel Chinese Shellcode Linked With Cyber Espionage Group BlackTech. Retrieved February 16, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareBendyBear

BendyBear has used byte randomization to obscure its behavior.

T1012
Query Registry
MalwareBendyBear

BendyBear can query the host's Registry key at HKEY_CURRENT_USER\Console\QuickEdit to retrieve data.

T1027.013
Encrypted/Encoded File
MalwareBendyBear

BendyBear has encrypted payloads using RC4 and XOR.

T1027.014
Polymorphic Code
MalwareBendyBear

BendyBear changes its runtime footprint during code execution to evade signature-based defenses.

T1105
Ingress Tool Transfer
MalwareBendyBear

BendyBear is designed to download an implant from a C2 server.

T1106
Native API
MalwareBendyBear

BendyBear can load and execute modules and Windows Application Programming (API) calls using standard shellcode API hashing.

T1124
System Time Discovery
MalwareBendyBear

BendyBear has the ability to determine local time on a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareBendyBear

BendyBear has decrypted function blocks using a XOR key during runtime to evade detection.

T1497.003
Time Based Checks
MalwareBendyBear

BendyBear can check for analysis environments and signs of debugging using the Windows API kernel32!GetTickCountKernel32 call.

T1571
Non-Standard Port
MalwareBendyBear

BendyBear has used a custom RC4 and XOR encrypted protocol over port 443 for C2.

T1573.001
Symmetric Cryptography
MalwareBendyBear

BendyBear communicates to a C2 server over port 443 using modified RC4 and XOR-encrypted chunks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.