ATT&CKReferencesLazarus RATANKBA

Lazarus RATANKBA

Lei, C., et al. (2018, January 24). Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool, an Evolved RATANKBA, and More. Retrieved May 22, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareRATANKBA

RATANKBA gathers the victim’s IP address via the ipconfig -all command.

T1047
Windows Management Instrumentation
MalwareRATANKBA

RATANKBA uses WMI to perform process monitoring.

T1055.001
Dynamic-link Library Injection
MalwareRATANKBA

RATANKBA performs a reflective DLL injection using a given pid.

T1057
Process Discovery
MalwareRATANKBA

RATANKBA lists the system’s processes.

T1059.001
PowerShell
MalwareRATANKBA

There is a variant of RATANKBA that uses a PowerShell script instead of the traditional PE form.

T1059.003
Windows Command Shell
MalwareRATANKBA

RATANKBA uses cmd.exe to execute commands.

T1071.001
Web Protocols
MalwareRATANKBA

RATANKBA uses HTTP/HTTPS for command and control communication.

T1082
System Information Discovery
MalwareRATANKBA

RATANKBA gathers information about the OS architecture, OS name, and OS version/Service pack.

T1105
Ingress Tool Transfer
MalwareRATANKBA

RATANKBA uploads and downloads information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.