M.Leveille, M., Sanmillan, I. (2021, February 2). Kobalos – A complex Linux threat to high performance computing infrastructure. Retrieved August 24, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareKobalos | Kobalos encrypts all strings using RC4 and bundles all functionality into a single function call. |
| T1056 Input Capture |
MalwareKobalos | Kobalos has used a compromised SSH client to capture the hostname, port, username and password used to establish an SSH connection from the compromised host. |
| T1059.004 Unix Shell |
MalwareKobalos | Kobalos can spawn a new pseudo-terminal and execute arbitrary commands at the command prompt. |
| T1070.003 Clear Command History |
MalwareKobalos | Kobalos can remove all command history on compromised hosts. |
| T1090.003 Multi-hop Proxy |
MalwareKobalos | Kobalos can chain together multiple compromised machines as proxies to reach their final targets. |
| T1205 Traffic Signaling |
MalwareKobalos | Kobalos is triggered by an incoming TCP connection to a legitimate service from a specific source port. |
| T1573.001 Symmetric Cryptography |
MalwareKobalos | Kobalos's post-authentication communication channel uses a 32-byte-long password with RC4 for inbound and outbound traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareKobalos | Kobalos's authentication and key exchange is performed using RSA-512. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.