ATT&CKReferencesTrend Micro Waterbear December 2019

Trend Micro Waterbear December 2019

Su, V. et al. (2019, December 11). Waterbear Returns, Uses API Hooking to Evade Security. Retrieved February 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareWaterbear

Waterbear can query the Registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\MTxOCI" to see if the value `OracleOcilib` exists.

T1027.005
Indicator Removal from Tools
MalwareWaterbear

Waterbear can scramble functions not to be executed again with random values.

T1027.013
Encrypted/Encoded File
MalwareWaterbear

Waterbear has used RC4 encrypted shellcode and encrypted functions.

T1049
System Network Connections Discovery
MalwareWaterbear

Waterbear can use API hooks on `GetExtendedTcpTable` to retrieve a table containing a list of TCP endpoints available to the application.

T1055
Process Injection
MalwareWaterbear

Waterbear can inject decrypted shellcode into the LanmanServer service.

T1055.003
Thread Execution Hijacking
MalwareWaterbear

Waterbear can use thread injection to inject shellcode into the process of security software.

T1057
Process Discovery
MalwareWaterbear

Waterbear can identify the process for a specific security product.

T1105
Ingress Tool Transfer
MalwareWaterbear

Waterbear can receive and load executables from remote C2 servers.

T1106
Native API
MalwareWaterbear

Waterbear can leverage API functions for execution.

T1112
Modify Registry
MalwareWaterbear

Waterbear has deleted certain values from the Registry to load a malicious DLL.

T1140
Deobfuscate/Decode Files or Information
MalwareWaterbear

Waterbear has the ability to decrypt its RC4 encrypted payload for execution.

T1518.001
Security Software Discovery
MalwareWaterbear

Waterbear can find the presence of a specific security software.

T1574.001
DLL
GroupBlackTech

BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories.

T1574.001
DLL
MalwareWaterbear

Waterbear has used DLL side loading to import and load a malicious DLL loader.

T1685
Disable or Modify Tools
MalwareWaterbear

Waterbear can hook the ZwOpenProcess and GetExtendedTcpTable APIs called by the process of a security product to hide PIDs and TCP records from detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.