ATT&CKReferencesRapid7 BlackBasta 2024

Rapid7 BlackBasta 2024

McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareDarkGate

DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present.

T1047
Windows Management Instrumentation
MalwareDarkGate

DarkGate has used WMI to execute files over the network and to obtain information about the domain.

T1055.012
Process Hollowing
MalwareDarkGate

DarkGate leverages process hollowing techniques to evade detection, such as decrypting the content of an encrypted PE file and injecting it into the process vbc.exe.

T1056.001
Keylogging
MalwareDarkGate

DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file.

T1057
Process Discovery
MalwareDarkGate

DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values.

T1059.001
PowerShell
MalwareDarkGate

DarkGate has used PowerShell to create a remote shell.

T1059.003
Windows Command Shell
MalwareDarkGate

DarkGate uses a malicious Windows Batch script to run the Windows code utility to retrieve follow-on script payloads. DarkGate has also used `cmd.exe` to create a remote shell.

T1070.004
File Deletion
MalwareDarkGate

DarkGate has deleted its staging directories.

T1082
System Information Discovery
MalwareDarkGate

DarkGate will gather various system information such as domain, display adapter description, operating system type and version, processor type, and RAM amount.

T1105
Ingress Tool Transfer
MalwareDarkGate

DarkGate retrieves cryptocurrency mining payloads and commands in encrypted traffic from its command and control server. DarkGate uses Windows Batch scripts executing the curl command to retrieve follow-on payloads. DarkGate has stolen `sitemanager.xml` and `recentservers.xml` from `%APPDATA%\FileZilla\` if present.

T1106
Native API
MalwareDarkGate

DarkGate uses the native Windows API CallWindowProc() to decode and launch encoded shellcode payloads during execution. DarkGate can call kernel mode functions directly to hide the use of process hollowing methods during execution. DarkGate has also used the `CreateToolhelp32Snapshot`, `GetFileAttributesA` and `CreateProcessA` functions to obtain a list of running processes, to check for security products and to execute its malware.

T1115
Clipboard Data
MalwareDarkGate

DarkGate starts a thread on execution that captures clipboard data and logs it to a predefined log file.

T1518.001
Security Software Discovery
MalwareDarkGate

DarkGate looks for various security products by process name using hard-coded values in the malware. DarkGate will not execute its keylogging thread if a process name associated with Trend Micro anti-virus is identified, or if runtime checks identify the presence of Kaspersky anti-virus. DarkGate will initiate a new thread if certain security products are identified on the victim, and recreate any malicious files associated with it if it determines they were removed by security software in a new system location.

T1529
System Shutdown/Reboot
MalwareDarkGate

DarkGate has used the `shutdown`command to shut down and/or restart the victim system.

T1539
Steal Web Session Cookie
MalwareDarkGate

DarkGate attempts to steal Opera cookies, if present, after terminating the related process.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkGate

DarkGate installation includes AutoIt script execution creating a shortcut to itself as an LNK object, such as bill.lnk, in the victim startup folder. DarkGate installation finishes with the creation of a registry Run key.

T1561.001
Disk Content Wipe
MalwareDarkGate

DarkGate has deleted all files in the Mozilla directory using the following command: `/c del /q /f /s C:\Users\User\AppData\Roaming\Mozilla\firefox*`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.