ATT&CKReferencesjRAT Symantec Aug 2018

jRAT Symantec Aug 2018

Sharma, R. (2018, August 15). Revamped jRAT Uses New Anti-Parsing Techniques. Retrieved September 21, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwarejRAT

jRAT’s Java payload is encrypted with AES. Additionally, backdoor files are encrypted using DES as a stream cipher. Later variants of jRAT also incorporated AV evasion methods such as Java bytecode obfuscation via the commercial Allatori obfuscation tool.

T1047
Windows Management Instrumentation
MalwarejRAT

jRAT uses WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

T1056.001
Keylogging
MalwarejRAT

jRAT has the capability to log keystrokes from the victim’s machine, both offline and online.

T1070.004
File Deletion
MalwarejRAT

jRAT has a function to delete files from the victim’s machine.

T1105
Ingress Tool Transfer
MalwarejRAT

jRAT can download and execute files.

T1113
Screen Capture
MalwarejRAT

jRAT has the capability to take screenshots of the victim’s machine.

T1125
Video Capture
MalwarejRAT

jRAT has the capability to capture video from a webcam.

T1518.001
Security Software Discovery
MalwarejRAT

jRAT can list security software, such as by using WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.