ATT&CKReferencesTrend Micro njRAT 2018

Trend Micro njRAT 2018

Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1012
Query Registry
MalwarenjRAT

njRAT can read specific registry values.

T1027.004
Compile After Delivery
MalwarenjRAT

njRAT has used AutoIt to compile the payload and main script into a single executable after delivery.

T1027.013
Encrypted/Encoded File
MalwarenjRAT

njRAT has included a base64 encoded executable.

T1041
Exfiltration Over C2 Channel
MalwarenjRAT

njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information.

T1056.001
Keylogging
MalwarenjRAT

njRAT is capable of logging keystrokes.

T1057
Process Discovery
MalwarenjRAT

njRAT can search a list of running processes for Tr.exe.

T1059.001
PowerShell
MalwarenjRAT

njRAT has executed PowerShell commands via auto-run registry key persistence.

T1070.004
File Deletion
MalwarenjRAT

njRAT is capable of deleting files.

T1070.009
Clear Persistence
MalwarenjRAT

njRAT is capable of manipulating and deleting registry keys, including those used for persistence.

T1071.001
Web Protocols
MalwarenjRAT

njRAT has used HTTP for C2 communications.

T1091
Replication Through Removable Media
MalwarenjRAT

njRAT can be configured to spread via removable drives.

T1105
Ingress Tool Transfer
MalwarenjRAT

njRAT can download files to the victim’s machine. APT-C-36 has used modified versions of njRAT to enable the download of .NET assemblies.

T1106
Native API
MalwarenjRAT

njRAT has used the ShellExecute() function within a script.

T1112
Modify Registry
MalwarenjRAT

njRAT can create, delete, or modify a specified Registry key or value.

T1113
Screen Capture
MalwarenjRAT

njRAT can capture screenshots of the victim’s machines.

T1120
Peripheral Device Discovery
MalwarenjRAT

njRAT will attempt to detect if the victim system has a camera during the initial infection. njRAT can also detect any removable drives connected to the system.

T1547.001
Registry Run Keys / Startup Folder
MalwarenjRAT

njRAT has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\ and dropped a shortcut in %STARTUP%.

T1555.003
Credentials from Web Browsers
MalwarenjRAT

njRAT has a module that steals passwords saved in victim web browsers.

T1568.001
Fast Flux DNS
MalwarenjRAT

njRAT has used a fast flux DNS for C2 IP resolution.

T1571
Non-Standard Port
MalwarenjRAT

njRAT has used port 1177 for HTTP C2 communications.

T1686.003
Windows Host Firewall
MalwarenjRAT

njRAT has modified the Windows firewall to allow itself to communicate through the firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.