ATT&CKReferencesTalos Konni May 2017

Talos Konni May 2017

Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareKONNI

KONNI can collect the IP address from the victim’s machine.

T1033
System Owner/User Discovery
MalwareKONNI

KONNI can collect the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareKONNI

KONNI has created a shortcut called "Anti virus service.lnk" in an apparent attempt to masquerade as a legitimate file.

T1041
Exfiltration Over C2 Channel
MalwareKONNI

KONNI has sent data and files to its C2 server.

T1056.001
Keylogging
MalwareKONNI

KONNI has the capability to perform keylogging.

T1059.001
PowerShell
MalwareKONNI

KONNI used PowerShell to download and execute a specific 64-bit version of the malware.

T1059.003
Windows Command Shell
MalwareKONNI

KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain.

T1070.004
File Deletion
MalwareKONNI

KONNI can delete files.

T1071.001
Web Protocols
MalwareKONNI

KONNI has used HTTP POST for C2.

T1082
System Information Discovery
MalwareKONNI

KONNI can gather the OS version, architecture information, hostname, and RAM size information from the victim’s machine and has used cmd /c systeminfo command to get a snapshot of the current system state of the target machine.

T1083
File and Directory Discovery
MalwareKONNI

A version of KONNI searches for filenames created with a previous version of the malware, suggesting different versions targeted the same victims and the versions may work together.

T1105
Ingress Tool Transfer
MalwareKONNI

KONNI can download files and execute them on the victim’s machine.

T1113
Screen Capture
MalwareKONNI

KONNI can take screenshots of the victim’s machine.

T1115
Clipboard Data
MalwareKONNI

KONNI had a feature to steal data from the clipboard.

T1547.001
Registry Run Keys / Startup Folder
MalwareKONNI

A version of KONNI has dropped a Windows shortcut into the Startup folder to establish persistence.

T1547.009
Shortcut Modification
MalwareKONNI

A version of KONNI drops a Windows shortcut on the victim’s machine to establish persistence.

T1555.003
Credentials from Web Browsers
MalwareKONNI

KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera.

T1680
Local Storage Discovery
MalwareKONNI

KONNI can gather information on connected drives and disk space from the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.