ATT&CKReferencesCisco MagicRAT 2022

Cisco MagicRAT 2022

Asheer Malhotra, Vitor Ventura & Jungsoo An, Cisco Talos. (2022, September 7). MagicRAT: Lazarus’ latest gateway into victim networks. Retrieved December 30, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareMagicRAT

MagicRAT collects system network information using commands such as `ipconfig /all`.

T1027.013
Encrypted/Encoded File
MalwareMagicRAT

MagicRAT stores base64 encoded command and contorl URLs in a configuraiton file, with each URL prefixed with the value `LR02DPt22R`.

T1036.005
Match Legitimate Resource Name or Location
MalwareMagicRAT

MagicRAT stores configuration data in files and file paths mimicking legitimate operating system resources.

T1036.008
Masquerade File Type
MalwareMagicRAT

MagicRAT can download additional executable payloads that masquerade as GIF files.

T1041
Exfiltration Over C2 Channel
MalwareMagicRAT

MagicRAT exfiltrates data via HTTP over existing command and control channels.

T1053.005
Scheduled Task
MalwareMagicRAT

MagicRAT can persist via scheduled tasks.

T1059.003
Windows Command Shell
MalwareMagicRAT

MagicRAT allows for the execution of arbitrary commands on the victim system.

T1070.004
File Deletion
MalwareMagicRAT

MagicRAT can delete files on victim systems, including itself.

T1071.001
Web Protocols
MalwareMagicRAT

MagicRAT uses HTTP POST communication for command and control.

T1082
System Information Discovery
MalwareMagicRAT

MagicRAT collects basic system information from victim machines.

T1105
Ingress Tool Transfer
MalwareMagicRAT

MagicRAT can import and execute additional payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareMagicRAT

MagicRAT stores command and control URLs using base64 encoding in the malware's configuration file.

T1547.001
Registry Run Keys / Startup Folder
MalwareMagicRAT

MagicRAT can persist using malicious LNK objects in the victim machine Startup folder.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.