Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarenjRAT | njRAT can collect data from a local system. |
| T1010 Application Window Discovery |
MalwarenjRAT | njRAT gathers information about opened windows during the initial infection. |
| T1018 Remote System Discovery |
MalwarenjRAT | njRAT can identify remote hosts on connected networks. |
| T1021.001 Remote Desktop Protocol |
MalwarenjRAT | njRAT has a module for performing remote desktop access. |
| T1033 System Owner/User Discovery |
MalwarenjRAT | njRAT enumerates the current user during the initial infection. |
| T1056.001 Keylogging |
MalwarenjRAT | njRAT is capable of logging keystrokes. |
| T1059.003 Windows Command Shell |
MalwarenjRAT | njRAT can launch a command shell interface for executing commands. |
| T1070.004 File Deletion |
MalwarenjRAT | njRAT is capable of deleting files. |
| T1082 System Information Discovery |
MalwarenjRAT | njRAT enumerates the victim operating system and computer name during the initial infection. |
| T1083 File and Directory Discovery |
MalwarenjRAT | njRAT can browse file systems using a file manager module. |
| T1091 Replication Through Removable Media |
MalwarenjRAT | njRAT can be configured to spread via removable drives. |
| T1105 Ingress Tool Transfer |
MalwarenjRAT | njRAT can download files to the victim’s machine. APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies. |
| T1112 Modify Registry |
MalwarenjRAT | njRAT can create, delete, or modify a specified Registry key or value. |
| T1120 Peripheral Device Discovery |
MalwarenjRAT | njRAT will attempt to detect if the victim system has a camera during the initial infection. njRAT can also detect any removable drives connected to the system. |
| T1125 Video Capture |
MalwarenjRAT | njRAT can access the victim's webcam. |
| T1132.001 Standard Encoding |
MalwarenjRAT | njRAT uses Base64 encoding for C2 traffic. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarenjRAT | njRAT has added persistence via the Registry key |
| T1555.003 Credentials from Web Browsers |
MalwarenjRAT | njRAT has a module that steals passwords saved in victim web browsers. |
| T1686.003 Windows Host Firewall |
MalwarenjRAT | njRAT has modified the Windows firewall to allow itself to communicate through the firewall. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.