ATT&CKReferencesUnit42 BabyShark Feb 2019

Unit42 BabyShark Feb 2019

Unit 42. (2019, February 22). New BabyShark Malware Targets U.S. National Security Think Tanks. Retrieved October 7, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareBabyShark

BabyShark has executed the reg query command for HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default.

T1016
System Network Configuration Discovery
MalwareBabyShark

BabyShark has executed the ipconfig /all command.

T1033
System Owner/User Discovery
MalwareBabyShark

BabyShark has executed the whoami command.

T1057
Process Discovery
MalwareBabyShark

BabyShark has executed the tasklist command.

T1059.003
Windows Command Shell
MalwareBabyShark

BabyShark has used cmd.exe to execute commands.

T1082
System Information Discovery
MalwareBabyShark

BabyShark has executed the ver command.

T1083
File and Directory Discovery
MalwareBabyShark

BabyShark has used dir to search for "programfiles" and "appdata".

T1132.001
Standard Encoding
MalwareBabyShark

BabyShark has encoded data using certutil before exfiltration.

T1547.001
Registry Run Keys / Startup Folder
MalwareBabyShark

BabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.