ATT&CKReferencesLumen KVBotnet 2023

Lumen KVBotnet 2023

Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples20

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
CampaignKV Botnet Activity

KV Botnet Activity gathers victim IP information during initial installation stages.

T1036
Masquerading
CampaignKV Botnet Activity

KV Botnet Activity involves changing process filename to pr_set_mm_exe_file and process name to pr_set_name during later infection stages.

T1036.004
Masquerade Task or Service
CampaignKV Botnet Activity

KV Botnet Activity installation steps include first identifying, then stopping, any process containing [kworker\/0:1], then renaming its initial installation stage to this process name.

T1055.009
Proc Memory
CampaignKV Botnet Activity

KV Botnet Activity final payload installation includes mounting and binding to the \/proc\/ filepath on the victim system to enable subsequent operation in memory while also removing on-disk artifacts.

T1057
Process Discovery
CampaignKV Botnet Activity

Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation.

T1059.004
Unix Shell
CampaignKV Botnet Activity

KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell.

T1070.004
File Deletion
CampaignKV Botnet Activity

KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device.

T1082
System Information Discovery
CampaignKV Botnet Activity

KV Botnet Activity includes use of native system tools, such as uname, to obtain information about victim device architecture, as well as gathering other system information such as the victim's hosts file and CPU utilization.

T1083
File and Directory Discovery
CampaignKV Botnet Activity

KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: \/usr\/sbin\/, \/usr\/bin\/, \/sbin\/, \/pfrm2.0\/bin\/, \/usr\/local\/bin\/.

T1095
Non-Application Layer Protocol
CampaignKV Botnet Activity

KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication.

T1105
Ingress Tool Transfer
CampaignKV Botnet Activity

KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes.

T1222.002
Linux and Mac Permissions
CampaignKV Botnet Activity

KV Botnet Activity altered permissions on downloaded tools and payloads to enable execution on victim machines.

T1518.001
Security Software Discovery
CampaignKV Botnet Activity

KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices.

T1546
Event Triggered Execution
CampaignKV Botnet Activity

KV Botnet Activity involves managing events on victim systems via libevent to execute a callback function when any running process contains the following references in their path without also having a reference to bioset: busybox, wget, curl, tftp, telnetd, or lua. If the bioset string is not found, the related process is terminated.

T1564.013
Bind Mounts
CampaignKV Botnet Activity

KV Botnet Activity leveraged a bind mount to bind itself to the `/proc/` file path before deleting its files from the `/tmp/` directory.

T1571
Non-Standard Port
CampaignKV Botnet Activity

KV Botnet Activity generates a random port number greater than 30,000 to serve as the listener for subsequent command and control activity.

T1573
Encrypted Channel
CampaignKV Botnet Activity

KV Botnet Activity command and control activity includes transmission of an RSA public key in communication from the server, but this is followed by subsequent negotiation stages that represent a form of handshake similar to TLS negotiation.

T1583.003
Virtual Private Server
CampaignKV Botnet Activity

KV Botnet Activity used acquired Virtual Private Servers as control systems for devices infected with KV Botnet malware.

T1584.008
Network Devices
CampaignKV Botnet Activity

KV Botnet Activity focuses on compromise of small office-home office (SOHO) network devices to build the subsequent botnet.

T1685
Disable or Modify Tools
CampaignKV Botnet Activity

KV Botnet Activity used various scripts to remove or disable security tools, such as http_watchdog and firewallsd, as well as tools related to other botnet infections, such as mips_ff, on victim devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.