ATT&CKReferencesMedium KONNI Jan 2020

Medium KONNI Jan 2020

Karmi, D. (2020, January 4). A Look Into Konni 2019 Campaign. Retrieved April 28, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareKONNI

KONNI has used FTP to exfiltrate reconnaissance data out.

T1057
Process Discovery
MalwareKONNI

KONNI has used the command cmd /c tasklist to get a snapshot of the current processes on the target machine.

T1059.003
Windows Command Shell
MalwareKONNI

KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain.

T1082
System Information Discovery
MalwareKONNI

KONNI can gather the OS version, architecture information, hostname, and RAM size information from the victim’s machine and has used cmd /c systeminfo command to get a snapshot of the current system state of the target machine.

T1112
Modify Registry
MalwareKONNI

KONNI has modified registry keys of ComSysApp, Svchost, and xmlProv on the machine to gain persistence.

T1132.001
Standard Encoding
MalwareKONNI

KONNI has used a custom base64 key to encode stolen data before exfiltration.

T1134.002
Create Process with Token
MalwareKONNI

KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user.

T1140
Deobfuscate/Decode Files or Information
MalwareKONNI

KONNI has used certutil to download and decode base64 encoded strings and has also devoted a custom section to performing all the components of the deobfuscation process.

T1218.011
Rundll32
MalwareKONNI

KONNI has used Rundll32 to execute its loader for privilege escalation purposes.

T1546.015
Component Object Model Hijacking
MalwareKONNI

KONNI has modified ComSysApp service to load the malicious DLL payload.

T1548.002
Bypass User Account Control
MalwareKONNI

KONNI has bypassed UAC by performing token impersonation as well as an RPC-based method, this included bypassing UAC set to “AlwaysNotify".

T1680
Local Storage Discovery
MalwareKONNI

KONNI can gather information on connected drives and disk space from the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.