ATT&CKReferencesKaspersky Adwind Feb 2016

Kaspersky Adwind Feb 2016

Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwarejRAT

jRAT can list local services.

T1016
System Network Configuration Discovery
MalwarejRAT

jRAT can gather victim internal and external IPs.

T1021.001
Remote Desktop Protocol
MalwarejRAT

jRAT can support RDP control.

T1027.002
Software Packing
MalwarejRAT

jRAT payloads have been packed.

T1029
Scheduled Transfer
MalwarejRAT

jRAT can be configured to reconnect at certain intervals.

T1037.005
Startup Items
MalwarejRAT

jRAT can list and manage startup entries.

T1049
System Network Connections Discovery
MalwarejRAT

jRAT can list network connections.

T1056.001
Keylogging
MalwarejRAT

jRAT has the capability to log keystrokes from the victim’s machine, both offline and online.

T1059.003
Windows Command Shell
MalwarejRAT

jRAT has command line access.

T1059.005
Visual Basic
MalwarejRAT

jRAT has been distributed as HTA files with VBScript.

T1059.007
JavaScript
MalwarejRAT

jRAT has been distributed as HTA files with JScript.

T1083
File and Directory Discovery
MalwarejRAT

jRAT can browse file systems.

T1090
Proxy
MalwarejRAT

jRAT can serve as a SOCKS proxy server.

T1105
Ingress Tool Transfer
MalwarejRAT

jRAT can download and execute files.

T1113
Screen Capture
MalwarejRAT

jRAT has the capability to take screenshots of the victim’s machine.

T1115
Clipboard Data
MalwarejRAT

jRAT can capture clipboard data.

T1120
Peripheral Device Discovery
MalwarejRAT

jRAT can map UPnP ports.

T1123
Audio Capture
MalwarejRAT

jRAT can capture microphone recordings.

T1125
Video Capture
MalwarejRAT

jRAT has the capability to capture video from a webcam.

T1518.001
Security Software Discovery
MalwarejRAT

jRAT can list security software, such as by using WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

T1552.001
Credentials In Files
MalwarejRAT

jRAT can capture passwords from common chat applications such as MSN Messenger, AOL, Instant Messenger, and and Google Talk.

T1552.004
Private Keys
MalwarejRAT

jRAT can steal keys for VPNs and cryptocurrency wallets.

T1555.003
Credentials from Web Browsers
MalwarejRAT

jRAT can capture passwords from common web browsers such as Internet Explorer, Google Chrome, and Firefox.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.