ATT&CKReferencesPalo Alto T9000 Feb 2016

Palo Alto T9000 Feb 2016

Grunzweig, J. and Miller-Osborn, J.. (2016, February 4). T9000: Advanced Modular Backdoor Uses Complex Anti-Analysis Techniques. Retrieved April 15, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareT9000

T9000 gathers and beacons the MAC and IP addresses during installation.

T1033
System Owner/User Discovery
MalwareT9000

T9000 gathers and beacons the username of the logged in account during installation. It will also gather the username of running processes to determine if it is running as SYSTEM.

T1082
System Information Discovery
MalwareT9000

T9000 gathers and beacons the operating system build number and CPU Architecture (32-bit/64-bit) during installation.

T1113
Screen Capture
MalwareT9000

T9000 can take screenshots of the desktop and target application windows, saving them to user directories as one byte XOR encrypted .dat files.

T1119
Automated Collection
MalwareT9000

T9000 searches removable storage devices for files with a pre-defined list of file extensions (e.g. * .doc, *.ppt, *.xls, *.docx, *.pptx, *.xlsx). Any matching files are encrypted and written to a local user directory.

T1120
Peripheral Device Discovery
MalwareT9000

T9000 searches through connected drives for removable storage devices.

T1123
Audio Capture
MalwareT9000

T9000 uses the Skype API to record audio and video calls. It writes encrypted data to %APPDATA%\Intel\Skype.

T1124
System Time Discovery
MalwareT9000

T9000 gathers and beacons the system time during installation.

T1125
Video Capture
MalwareT9000

T9000 uses the Skype API to record audio and video calls. It writes encrypted data to %APPDATA%\Intel\Skype.

T1518.001
Security Software Discovery
MalwareT9000

T9000 performs checks for various antivirus and security products during installation.

T1546.010
AppInit DLLs
MalwareT9000

If a victim meets certain criteria, T9000 uses the AppInit_DLL functionality to achieve persistence by ensuring that every user mode process that is spawned will load its malicious DLL, ResN32.dll. It does this by creating the following Registry keys: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs – %APPDATA%\Intel\ResN32.dll and HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs – 0x1.

T1560.003
Archive via Custom Method
MalwareT9000

T9000 encrypts collected data using a single byte XOR key.

T1574.001
DLL
MalwareT9000

During the T9000 installation process, it drops a copy of the legitimate Microsoft binary igfxtray.exe. The executable contains a side-loading weakness which is used to load a portion of the malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.