ATT&CKReferencesSecureworks Karagany July 2019

Secureworks Karagany July 2019

Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareTrojan.Karagany

Trojan.Karagany can monitor the titles of open windows to identify specific keywords.

T1016
System Network Configuration Discovery
MalwareTrojan.Karagany

Trojan.Karagany can gather information on the network configuration of a compromised host.

T1027
Obfuscated Files or Information
MalwareTrojan.Karagany

Trojan.Karagany can base64 encode and AES-128-CBC encrypt data prior to transmission.

T1027.002
Software Packing
MalwareTrojan.Karagany

Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer.

T1033
System Owner/User Discovery
MalwareTrojan.Karagany

Trojan.Karagany can gather information about the user on a compromised host.

T1049
System Network Connections Discovery
MalwareTrojan.Karagany

Trojan.Karagany can use netstat to collect a list of network connections.

T1055.003
Thread Execution Hijacking
MalwareTrojan.Karagany

Trojan.Karagany can inject a suspended thread of its own process into a new process and initiate via the ResumeThread API.

T1056.001
Keylogging
MalwareTrojan.Karagany

Trojan.Karagany can capture keystrokes on a compromised host.

T1057
Process Discovery
MalwareTrojan.Karagany

Trojan.Karagany can use Tasklist to collect a list of running tasks.

T1059.003
Windows Command Shell
MalwareTrojan.Karagany

Trojan.Karagany can perform reconnaissance commands on a victim machine via a cmd.exe process.

T1070.004
File Deletion
MalwareTrojan.Karagany

Trojan.Karagany has used plugins with a self-delete capability.

T1071.001
Web Protocols
MalwareTrojan.Karagany

Trojan.Karagany can communicate with C2 via HTTP POST requests.

T1074.001
Local Data Staging
MalwareTrojan.Karagany

Trojan.Karagany can create directories to store plugin output and stage data for exfiltration.

T1082
System Information Discovery
MalwareTrojan.Karagany

Trojan.Karagany can capture information regarding the victim's OS, security, and hardware configuration.

T1083
File and Directory Discovery
MalwareTrojan.Karagany

Trojan.Karagany can enumerate files and directories on a compromised host.

T1105
Ingress Tool Transfer
MalwareTrojan.Karagany

Trojan.Karagany can upload, download, and execute files on the victim.

T1113
Screen Capture
MalwareTrojan.Karagany

Trojan.Karagany can take a desktop screenshot and save the file into \ProgramData\Mail\MailAg\shot.png.

T1497.001
System Checks
MalwareTrojan.Karagany

Trojan.Karagany can detect commonly used and generic virtualization platforms based primarily on drivers and file paths.

T1547.001
Registry Run Keys / Startup Folder
MalwareTrojan.Karagany

Trojan.Karagany can create a link to itself in the Startup folder to automatically start itself upon system restart.

T1555.003
Credentials from Web Browsers
MalwareTrojan.Karagany

Trojan.Karagany can steal data and credentials from browsers.

T1573.002
Asymmetric Cryptography
MalwareTrojan.Karagany

Trojan.Karagany can secure C2 communications with SSL and TLS.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.