ATT&CKReferencesTalent-Jump Clambling February 2020

Talent-Jump Clambling February 2020

Chen, T. and Chen, Z. (2020, February 17). CLAMBLING - A New Backdoor Base On Dropbox. Retrieved November 12, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareClambling

Clambling has the ability to enumerate Registry keys, including KEY_CURRENT_USER\Software\Bitcoin\Bitcoin-Qt\strDataDir to search for a bitcoin wallet.

T1016
System Network Configuration Discovery
MalwareClambling

Clambling can enumerate the IP address of a compromised machine.

T1033
System Owner/User Discovery
MalwareClambling

Clambling can identify the username on a compromised host.

T1056.001
Keylogging
MalwareClambling

Clambling can capture keystrokes on a compromised host.

T1082
System Information Discovery
MalwareClambling

Clambling can discover the hostname, computer name, and Windows version of a targeted machine.

T1083
File and Directory Discovery
MalwareClambling

Clambling can browse directories on a compromised host.

T1102.002
Bidirectional Communication
MalwareClambling

Clambling can use Dropbox to download malicious payloads, send commands, and receive information.

T1115
Clipboard Data
MalwareClambling

Clambling has the ability to capture and store clipboard data.

T1125
Video Capture
MalwareClambling

Clambling can record screen content in AVI format.

T1140
Deobfuscate/Decode Files or Information
MalwareClambling

Clambling can deobfuscate its payload prior to execution.

T1543.003
Windows Service
MalwareClambling

Clambling can register itself as a system service to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareClambling

Clambling can establish persistence by adding a Registry run key.

T1548.002
Bypass User Account Control
MalwareClambling

Clambling has the ability to bypass UAC using a `passuac.dll` file.

T1567.002
Exfiltration to Cloud Storage
MalwareClambling

Clambling can send files from a victim's machine to Dropbox.

T1574.001
DLL
MalwareClambling

Clambling can store a file named `mpsvc.dll`, which opens a malicious `mpsvc.mui` file, in the same folder as the legitimate Microsoft executable `MsMpEng.exe` to gain execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.