Mohammad Kazem Hassan Nejad, WithSecure. (2024, April 17). KAPEKA A novel backdoor spotted in Eastern Europe. Retrieved January 6, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareKapeka | Kapeka queries registry values for stored configuration information. |
| T1027.013 Encrypted/Encoded File |
MalwareKapeka | Kapeka utilizes AES-256 (CBC mode), XOR, and RSA-2048 encryption schemas for various configuration and other objects. |
| T1036.008 Masquerade File Type |
MalwareKapeka | Kapeka masquerades as a Microsoft Word Add-In file, with the extension `.wll`, but is a malicious DLL file. |
| T1053.005 Scheduled Task |
MalwareKapeka | Kapeka persists via scheduled tasks. |
| T1059.003 Windows Command Shell |
MalwareKapeka | Kapeka allows for arbitrary Windows command execution. |
| T1070.009 Clear Persistence |
MalwareKapeka | Kapeka will clear registry values used for persistent configuration storage when uninstalled. |
| T1071.001 Web Protocols |
MalwareKapeka | Kapeka utilizes HTTP for command and control. |
| T1082 System Information Discovery |
MalwareKapeka | Kapeka utilizes WinAPI calls and registry queries to gather system information. |
| T1090 Proxy |
MalwareKapeka | Kapeka can identify system proxy settings via `WinHttpGetIEProxyConfigForCurrentUser()` during initialization and utilize these settings for subsequent command and control operations. |
| T1106 Native API |
MalwareKapeka | Kapeka utilizes WinAPI calls to gather victim system information. |
| T1112 Modify Registry |
MalwareKapeka | Kapeka writes persistent configuration information to the victim host registry. |
| T1132.001 Standard Encoding |
MalwareKapeka | Kapeka utilizes JSON objects to send and receive information from command and control nodes. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKapeka | Kapeka utilizes obfuscated JSON structures for various data storage and configuration management items. |
| T1218.011 Rundll32 |
MalwareKapeka | Kapeka is a Windows DLL file executed via ordinal by `rundll32.exe`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.