ATT&CKReferencesPrevx Carberp March 2011

Prevx Carberp March 2011

Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareCarberp

Carberp has searched the Image File Execution Options registry key for "Debugger" within every subkey.

T1014
Rootkit
MalwareCarberp

Carberp has used user mode rootkit techniques to remain hidden on the system.

T1021.005
VNC
MalwareCarberp

Carberp can start a remote VNC session by downloading a new plugin.

T1027.013
Encrypted/Encoded File
MalwareCarberp

Carberp has used XOR-based encryption to mask C2 server locations within the trojan.

T1036.005
Match Legitimate Resource Name or Location
MalwareCarberp

Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe".

T1041
Exfiltration Over C2 Channel
MalwareCarberp

Carberp has exfiltrated data via HTTP to already established C2 servers.

T1055.004
Asynchronous Procedure Call
MalwareCarberp

Carberp has queued an APC routine to explorer.exe by calling ZwQueueApcThread.

T1056.004
Credential API Hooking
MalwareCarberp

Carberp has hooked several Windows API functions to steal credentials.

T1068
Exploitation for Privilege Escalation
MalwareCarberp

Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.

T1082
System Information Discovery
MalwareCarberp

Carberp has collected the operating system version from the infected system.

T1105
Ingress Tool Transfer
MalwareCarberp

Carberp can download and execute new plugins from the C2 server.

T1113
Screen Capture
MalwareCarberp

Carberp can capture display screenshots with the screens_dll.dll plugin.

T1185
Browser Session Hijacking
MalwareCarberp

Carberp has captured credentials when a user performs login through a SSL session.

T1518.001
Security Software Discovery
MalwareCarberp

Carberp has queried the infected system's registry searching for specific registry keys associated with antivirus products.

T1547.001
Registry Run Keys / Startup Folder
MalwareCarberp

Carberp has maintained persistence by placing itself inside the current user's startup folder.

T1555
Credentials from Password Stores
MalwareCarberp

Carberp's passw.plug plugin can gather account information from multiple instant messaging, email, and social media services, as well as FTP, VNC, and VPN clients.

T1555.003
Credentials from Web Browsers
MalwareCarberp

Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome.

T1685
Disable or Modify Tools
MalwareCarberp

Carberp has attempted to disable security software by creating a suspended process for the security software and injecting code to delete antivirus core files when the process is resumed.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.