ATT&CKReferencesGroup IB GrimAgent July 2021

Group IB GrimAgent July 2021

Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples25

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareGrimAgent

GrimAgent can pad C2 messages with random generated values.

T1005
Data from Local System
MalwareGrimAgent

GrimAgent can collect data and files from a compromised host.

T1016
System Network Configuration Discovery
MalwareGrimAgent

GrimAgent can enumerate the IP and domain of a target system.

T1027
Obfuscated Files or Information
MalwareGrimAgent

GrimAgent has used Rotate on Right (RoR) and Rotate on Left (RoL) functionality to encrypt strings.

T1027.001
Binary Padding
MalwareGrimAgent

GrimAgent has the ability to add bytes to change the file hash.

T1033
System Owner/User Discovery
MalwareGrimAgent

GrimAgent can identify the user id on a target machine.

T1041
Exfiltration Over C2 Channel
MalwareGrimAgent

GrimAgent has sent data related to a compromise host over its C2 channel.

T1053.005
Scheduled Task
MalwareGrimAgent

GrimAgent has the ability to set persistence using the Task Scheduler.

T1059.003
Windows Command Shell
MalwareGrimAgent

GrimAgent can use the Windows Command Shell to execute commands, including its own removal.

T1070.004
File Deletion
MalwareGrimAgent

GrimAgent can delete old binaries on a compromised host.

T1070.009
Clear Persistence
MalwareGrimAgent

GrimAgent can delete previously created tasks on a compromised host.

T1071.001
Web Protocols
MalwareGrimAgent

GrimAgent has the ability to use HTTP for C2 communications.

T1082
System Information Discovery
MalwareGrimAgent

GrimAgent can collect the OS, and build version on a compromised host.

T1083
File and Directory Discovery
MalwareGrimAgent

GrimAgent has the ability to enumerate files and directories on a compromised host.

T1105
Ingress Tool Transfer
MalwareGrimAgent

GrimAgent has the ability to download and execute additional payloads.

T1106
Native API
MalwareGrimAgent

GrimAgent can use Native API including GetProcAddress and ShellExecuteW.

T1132.001
Standard Encoding
MalwareGrimAgent

GrimAgent can base64 encode C2 replies.

T1140
Deobfuscate/Decode Files or Information
MalwareGrimAgent

GrimAgent can use a decryption algorithm for strings based on Rotate on Right (RoR) and Rotate on Left (RoL) functionality.

T1480.002
Mutual Exclusion
MalwareGrimAgent

GrimAgent uses the last 64 bytes of the binary to compute a mutex name. If the generated name is invalid, it will default to the generic `mymutex`.

T1497.003
Time Based Checks
MalwareGrimAgent

GrimAgent can sleep for 195 - 205 seconds after payload execution and before deleting its task.

T1547.001
Registry Run Keys / Startup Folder
MalwareGrimAgent

GrimAgent can set persistence with a Registry run key.

T1573.001
Symmetric Cryptography
MalwareGrimAgent

GrimAgent can use an AES key to encrypt C2 communications.

T1573.002
Asymmetric Cryptography
MalwareGrimAgent

GrimAgent can use a hardcoded server public RSA key to encrypt the first request to C2.

T1614
System Location Discovery
MalwareGrimAgent

GrimAgent can identify the country code on a compromised host.

T1614.001
System Language Discovery
MalwareGrimAgent

GrimAgent has used Accept-Language to identify hosts in the United Kingdom, United States, France, and Spain.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.