ATT&CKReferencesS2W Troll Stealer 2024

S2W Troll Stealer 2024

Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareTroll Stealer

Troll Stealer gathers information from infected systems such as SSH information from the victim's `.ssh` directory. Troll Stealer collects information from local FileZilla installations and Microsoft Sticky Note.

T1016
System Network Configuration Discovery
MalwareTroll Stealer

Troll Stealer collects the MAC address of victim devices.

T1027.002
Software Packing
MalwareTroll Stealer

Troll Stealer has been delivered as a VMProtect-packed binary.

T1036.005
Match Legitimate Resource Name or Location
MalwareTroll Stealer

Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file.

T1041
Exfiltration Over C2 Channel
MalwareTroll Stealer

Troll Stealer exfiltrates collected information to its command and control infrastructure.

T1059.001
PowerShell
MalwareTroll Stealer

Troll Stealer creates and executes a PowerShell script to delete itself.

T1059.003
Windows Command Shell
MalwareTroll Stealer

Troll Stealer can create and execute Windows batch scripts.

T1070.004
File Deletion
MalwareTroll Stealer

Troll Stealer creates and can execute a BAT script that will delete the malware.

T1071.001
Web Protocols
MalwareTroll Stealer

Troll Stealer uses HTTP to communicate to command and control infrastructure.

T1074.001
Local Data Staging
MalwareTroll Stealer

Troll Stealer encrypts gathered information on victim devices prior to exfiltrating it through command and control infrastructure.

T1082
System Information Discovery
MalwareTroll Stealer

Troll Stealer can collect local system information.

T1083
File and Directory Discovery
MalwareTroll Stealer

Troll Stealer can enumerate and collect items from local drives and folders.

T1090
Proxy
MalwareGoBear

GoBear implements SOCKS5 proxy functionality.

T1113
Screen Capture
MalwareTroll Stealer

Troll Stealer can capture screenshots from victim machines.

T1132.001
Standard Encoding
MalwareTroll Stealer

Troll Stealer performs XOR encryption and Base64 encoding of data prior to sending to command and control infrastructure.

T1213
Data from Information Repositories
MalwareTroll Stealer

Troll Stealer gathers information from the Government Public Key Infrastructure (GPKI) folder, associated with South Korean government public key infrastructure, on infected systems.

T1217
Browser Information Discovery
MalwareTroll Stealer

Troll Stealer collects information from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions.

T1218.011
Rundll32
MalwareTroll Stealer

Troll Stealer is dropped as a DLL file and executed via `rundll32.exe` by its installer.

T1480.002
Mutual Exclusion
MalwareTroll Stealer

Troll Stealer creates a mutex during installation to prevent duplicate execution.

T1539
Steal Web Session Cookie
GroupKimsuky

Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies.

T1552.004
Private Keys
MalwareTroll Stealer

Troll Stealer collects all data in victim `.ssh` folders by creating a compressed copy that is subsequently exfiltrated to command and control infrastructure. Troll Stealer also collects key information associated with the Government Public Key Infrastructure (GPKI) service for South Korean government information systems.

T1553.002
Code Signing
MalwareGoBear

GoBear uses stolen legitimate code signing certificates for defense evasion.

T1553.002
Code Signing
MalwareTroll Stealer

Troll Stealer, along with its associated dropper, utilizes legitimate, stolen code signing certificates.

T1553.002
Code Signing
GroupKimsuky

Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper.

T1560
Archive Collected Data
MalwareTroll Stealer

Troll Stealer compresses stolen data prior to exfiltration.

T1573.001
Symmetric Cryptography
MalwareTroll Stealer

Troll Stealer encrypts data sent to command and control infrastructure using a combination of RC4 and RSA-4096 algorithms.

T1588.003
Code Signing Certificates
GroupKimsuky

Kimsuky has stolen a valid certificate that is used to sign the malware and the dropper.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.