ATT&CKReferencesSymantec Frutas Feb 2013

Symantec Frutas Feb 2013

Bingham, J. (2013, February 11). Cross-Platform Frutas RAT Builder and Back Door. Retrieved April 23, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwarejRAT

jRAT’s Java payload is encrypted with AES. Additionally, backdoor files are encrypted using DES as a stream cipher. Later variants of jRAT also incorporated AV evasion methods such as Java bytecode obfuscation via the commercial Allatori obfuscation tool.

T1057
Process Discovery
MalwarejRAT

jRAT can query and kill system processes.

T1082
System Information Discovery
MalwarejRAT

jRAT collects information about the OS (version, build type, install date) as well as system up-time upon receiving a connection from a backdoor.

T1083
File and Directory Discovery
MalwarejRAT

jRAT can browse file systems.

T1105
Ingress Tool Transfer
MalwarejRAT

jRAT can download and execute files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.