ATT&CKReferencesRecordedFuture WhisperGate Jan 2022

RecordedFuture WhisperGate Jan 2022

Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareWhisperGate

WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage.

T1055.012
Process Hollowing
MalwareWhisperGate

WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`.

T1106
Native API
MalwareWhisperGate

WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls.

T1497.003
Time Based Checks
MalwareWhisperGate

WhisperGate can pause for 20 seconds to bypass antivirus solutions.

T1620
Reflective Code Loading
MalwareWhisperGate

WhisperGate's downloader can reverse its third stage file bytes and reflectively load the file as a .NET assembly.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.