ATT&CKReferencesFidelis njRAT June 2013

Fidelis njRAT June 2013

Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarenjRAT

njRAT can collect data from a local system.

T1010
Application Window Discovery
MalwarenjRAT

njRAT gathers information about opened windows during the initial infection.

T1018
Remote System Discovery
MalwarenjRAT

njRAT can identify remote hosts on connected networks.

T1021.001
Remote Desktop Protocol
MalwarenjRAT

njRAT has a module for performing remote desktop access.

T1033
System Owner/User Discovery
MalwarenjRAT

njRAT enumerates the current user during the initial infection.

T1056.001
Keylogging
MalwarenjRAT

njRAT is capable of logging keystrokes.

T1059.003
Windows Command Shell
MalwarenjRAT

njRAT can launch a command shell interface for executing commands.

T1070.004
File Deletion
MalwarenjRAT

njRAT is capable of deleting files.

T1082
System Information Discovery
MalwarenjRAT

njRAT enumerates the victim operating system and computer name during the initial infection.

T1083
File and Directory Discovery
MalwarenjRAT

njRAT can browse file systems using a file manager module.

T1091
Replication Through Removable Media
MalwarenjRAT

njRAT can be configured to spread via removable drives.

T1105
Ingress Tool Transfer
MalwarenjRAT

njRAT can download files to the victim’s machine. APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies.

T1112
Modify Registry
MalwarenjRAT

njRAT can create, delete, or modify a specified Registry key or value.

T1120
Peripheral Device Discovery
MalwarenjRAT

njRAT will attempt to detect if the victim system has a camera during the initial infection. njRAT can also detect any removable drives connected to the system.

T1125
Video Capture
MalwarenjRAT

njRAT can access the victim's webcam.

T1132.001
Standard Encoding
MalwarenjRAT

njRAT uses Base64 encoding for C2 traffic.

T1547.001
Registry Run Keys / Startup Folder
MalwarenjRAT

njRAT has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\ and dropped a shortcut in %STARTUP%.

T1555.003
Credentials from Web Browsers
MalwarenjRAT

njRAT has a module that steals passwords saved in victim web browsers.

T1686.003
Windows Host Firewall
MalwarenjRAT

njRAT has modified the Windows firewall to allow itself to communicate through the firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.