ATT&CKReferencesCISA ComRAT Oct 2020

CISA ComRAT Oct 2020

CISA. (2020, October 29). Malware Analysis Report (AR20-303A). Retrieved December 9, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareComRAT

ComRAT has encrypted its virtual file system using AES-256 in XTS mode.

T1027.009
Embedded Payloads
MalwareComRAT

ComRAT has embedded a XOR encrypted communications module inside the orchestrator module.

T1027.010
Command Obfuscation
MalwareComRAT

ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts.

T1027.011
Fileless Storage
MalwareComRAT

ComRAT has stored encrypted orchestrator code and payloads in the Registry.

T1053.005
Scheduled Task
MalwareComRAT

ComRAT has used a scheduled task to launch its PowerShell loader.

T1055.001
Dynamic-link Library Injection
MalwareComRAT

ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process.

T1059.001
PowerShell
MalwareComRAT

ComRAT has used PowerShell to load itself every time a user logs in to the system. ComRAT can execute PowerShell scripts loaded into memory or from the file system.

T1071.001
Web Protocols
MalwareComRAT

ComRAT has used HTTP requests for command and control.

T1102.002
Bidirectional Communication
MalwareComRAT

ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information.

T1112
Modify Registry
MalwareComRAT

ComRAT has modified Registry values to store encrypted orchestrator code and payloads.

T1124
System Time Discovery
MalwareComRAT

ComRAT has checked the victim system's date and time to perform tasks during business hours (9 to 5, Monday to Friday).

T1140
Deobfuscate/Decode Files or Information
MalwareComRAT

ComRAT has used unique per machine passwords to decrypt the orchestrator payload and a hardcoded XOR key to decrypt its communications module. ComRAT has also used a unique password to decrypt the file used for its hidden file system.

T1573.002
Asymmetric Cryptography
MalwareComRAT

ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.