ATT&CKReferencesWithSecure Kapeka 2024

WithSecure Kapeka 2024

Mohammad Kazem Hassan Nejad, WithSecure. (2024, April 17). KAPEKA A novel backdoor spotted in Eastern Europe. Retrieved January 6, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareKapeka

Kapeka queries registry values for stored configuration information.

T1027.013
Encrypted/Encoded File
MalwareKapeka

Kapeka utilizes AES-256 (CBC mode), XOR, and RSA-2048 encryption schemas for various configuration and other objects.

T1036.008
Masquerade File Type
MalwareKapeka

Kapeka masquerades as a Microsoft Word Add-In file, with the extension `.wll`, but is a malicious DLL file.

T1053.005
Scheduled Task
MalwareKapeka

Kapeka persists via scheduled tasks.

T1059.003
Windows Command Shell
MalwareKapeka

Kapeka allows for arbitrary Windows command execution.

T1070.009
Clear Persistence
MalwareKapeka

Kapeka will clear registry values used for persistent configuration storage when uninstalled.

T1071.001
Web Protocols
MalwareKapeka

Kapeka utilizes HTTP for command and control.

T1082
System Information Discovery
MalwareKapeka

Kapeka utilizes WinAPI calls and registry queries to gather system information.

T1090
Proxy
MalwareKapeka

Kapeka can identify system proxy settings via `WinHttpGetIEProxyConfigForCurrentUser()` during initialization and utilize these settings for subsequent command and control operations.

T1106
Native API
MalwareKapeka

Kapeka utilizes WinAPI calls to gather victim system information.

T1112
Modify Registry
MalwareKapeka

Kapeka writes persistent configuration information to the victim host registry.

T1132.001
Standard Encoding
MalwareKapeka

Kapeka utilizes JSON objects to send and receive information from command and control nodes.

T1140
Deobfuscate/Decode Files or Information
MalwareKapeka

Kapeka utilizes obfuscated JSON structures for various data storage and configuration management items.

T1218.011
Rundll32
MalwareKapeka

Kapeka is a Windows DLL file executed via ordinal by `rundll32.exe`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.